CVE-2024-51547
Credentials Disclosure - keys
Description
ABB became aware of vulnerabilities in the product versions listed as affected in the advisory. ASPECT devices are not intended to be internet-facing. A product advisory issued in June 2023 informed customers of this already. An attacker who successfully exploits these vulnerabilities could gain unauthorized access and potentially compromise the system's - and log-file - confidentiality, integrity and availability. ABB requires, as noted in previous security advisories and user documentation, that ASPECT should not be exposed to the internet or any other insecure network. Note: In order to exploit an ASPECT, an attacker would need a misconfigured system. ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-51547 and every CVE in our database. Create a free account — no credit card required.
Create Free Account