Sensitive System Information at Risk Due to Local File Inclusion Vulnerabilities
CVE-2024-51541
7.5HIGH
What is CVE-2024-51541?
ABB products ASPECT, NEXUS, and MATRIX Series versions v3.08.02 are susceptible to Local File Inclusion vulnerabilities. These flaws may enable malicious actors to gain unauthorized access to sensitive system information. This poses significant risks, including potential data exfiltration and compromise of system integrity, prompting immediate attention from organizations utilizing these affected products. Timely patching and mitigation strategies are essential to safeguard critical infrastructure from these vulnerabilities.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.08.02
MATRIX Series Linux 0 <= 3.08.02
NEXUS Series Linux 0 <= 3.08.02
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure