CVE-2024-48845 describes weak password reset rules in ABB ASPECT, NEXUS Series, and MATRIX Series (all v3.07.02) that allow for the storage of weak passwords, potentially leading to unauthorized administrative or application access. This vulnerability carries a critical CVSS score of 9.8, indicating a network-exploitable flaw with low attack complexity, requiring no user interaction, and resulting in high impact to confidentiality, integrity, and availability. While not currently on CISA's KEV catalog or showing active exploitation, public exploit code (EDB-52221) exists, and its FAUCET Risk Score of 94/100 suggests a high potential for exploitation despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-2_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-256_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-96_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:nexus-2128_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:nexus-2128-a_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.