Username Enumeration Vulnerabilities Affect ABB ASPECT, NEXUS, and MATRIX
CVE-2024-51545
9.8CRITICAL
What is CVE-2024-51545?
The vulnerability permits unauthorized users to exploit username enumeration weaknesses, leading to potential misuse of application-level functions. This includes functionalities such as adding, deleting, modifying, and listing usernames within the application. Affected products, particularly ABB ASPECT and NEXUS Series versions 3.08.02, are susceptible to these risks, making it imperative for users to review security measures and implement appropriate safeguards.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.08.02
MATRIX Series Linux 0 <= 3.08.02
NEXUS Series Linux 0 <= 3.08.02
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure