← back
CVE-2024-51546highCWE-1287

Credentails Disclosure

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.7epss 1.5%
from disclosure to weapon131 days
Published on NVDDec 5
1st PoC+131d
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

A security flaw allows unauthorized access to backup files stored on affected ABB systems, potentially exposing sensitive configuration and credential information. This can lead to unauthorized system access and data compromise.

Technical detail

This credential disclosure vulnerability permits attackers to access on-board project backup bundles without proper authorization. Exploitation requires network access to the affected ABB ASPECT Enterprise, NEXUS Series, or MATRIX Series v3.08.02 systems; successful compromise may expose authentication credentials and critical system configurations.

Summary generated and translated by AI from the official description.
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.