CVE-2024-48845
published 2024-12-05CVE-2024-48845: Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
1.83%
76.5th percentile
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.
Affected products:
ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | aspect-ent-12_firmware | <= 3.07.02 | — |
| abb | aspect-ent-256_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-2_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-96_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-enterprise | <= 3.07.02 | — |
| abb | matrix-11_firmware | <= 3.07.02 | — |
| abb | matrix-216_firmware | <= 3.07.02 | — |
| abb | matrix-232_firmware | <= 3.07.02 | — |
| abb | matrix-264_firmware | <= 3.07.02 | — |
| abb | matrix-296_firmware | <= 3.07.02 | — |
| abb | matrix_series | <= 3.07.02 | — |
| abb | nexus-2128-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-264_firmware | <= 3.07.02 | — |
| abb | nexus_series | <= 3.07.02 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable endpoint is userManagement.php on ABB Cylon Aspect 3.07.02; monitor for weak or single-character password submissions to this endpoint ↗
- →Weak Password Reset Rules vulnerability may allow storage of weak passwords; audit password policy enforcement on ASPECT-Enterprise, NEXUS Series, and MATRIX Series v3.07.02 admin interfaces ↗
- ·Affected versions are specifically v3.07.02 across all three product lines; scope detection to these versions only ↗
- ·Affected product families include NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, and ASPECT-Studio; ensure all variants are covered in asset inventory ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8297-wvjg-5vxg: Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admi
ghsa_unreviewed·2024-12-05
CVE-2024-48845 [CRITICAL] CWE-521 GHSA-8297-wvjg-5vxg: Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admi
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.
Affected products:
ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02
CISA ICS
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
cisa_ics·2025-01-07·CVSS 8.7
[HIGH] ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
ICS Advisory
##
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
Release DateJanuary 07, 2025
Alert CodeICSA-25-007-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: ASPECT-Enterprise, NEXUS, and MATRIX series
- Vulnerabilities: Files or Directories Accessible to External Parties, Improper Validation of Specified Type of Input, Cleartext Transmission of Sensitive Information, Cross-site Scripting, Server-Side Request Forgery (SSRF), Improper Neutralization of Special Elements in Data Query Logic, Allocation of Resources Without Limits or Throttling, Weak Password Requirements, Cr
No detection rules found.
No writeups or analysis indexed.
2024-12-05
Published