Username Enumeration Vulnerabilities Affect ABB ASPECT, NEXUS, and MATRIX
CVE-2024-51545

9.8CRITICAL

Key Information:

Vendor

Abb

Vendor
CVE Published:
5 December 2024

What is CVE-2024-51545?

The vulnerability permits unauthorized users to exploit username enumeration weaknesses, leading to potential misuse of application-level functions. This includes functionalities such as adding, deleting, modifying, and listing usernames within the application. Affected products, particularly ABB ASPECT and NEXUS Series versions 3.08.02, are susceptible to these risks, making it imperative for users to review security measures and implement appropriate safeguards.

Affected Version(s)

ASPECT-Enterprise Linux 0 <= 3.08.02

MATRIX Series Linux 0 <= 3.08.02

NEXUS Series Linux 0 <= 3.08.02

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
.
CVE-2024-51545 : Username Enumeration Vulnerabilities Affect ABB ASPECT, NEXUS, and MATRIX