CVE-2024-13951 is a high-severity vulnerability (CVSS 7.6) affecting ASPECT, NEXUS, and MATRIX Series products through version 3.*. It involves predictable salt in one-way hashes, which could lead to exposure of sensitive information and allow an attacker to compromise data integrity and availability. The attack requires low privileges and network access, but no user interaction. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ABB | ASPECT-Enterprise | >= 0, <= 3.*CNA affecteddefault affected | |
| ABB | MATRIX Series | >= 0, <= 3.*CNA affecteddefault unaffected | |
| ABB | NEXUS Series | >= 0, <= 3.*CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.