← back
CVE-2024-51544highCWE-15

Service Control

26Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 14%
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
In short

A vulnerability in ABB service management software allows unauthorized users to restart services and change virtual machine settings, potentially disrupting operations or gaining control over critical infrastructure.

Technical detail

Service Control CWE-15 vulnerability enables improper access to service restart and VM configuration endpoints in ABB ASPECT, NEXUS, and MATRIX v3.08.02. Exploitation requires network access to affected components; successful exploitation allows arbitrary service manipulation and system reconfiguration with high integrity and availability impact.

Summary generated and translated by AI from the official description.
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:L/SI:L/SA:L