CVE-2024-51546 is a high-severity credentials disclosure vulnerability affecting ABB ASPECT, NEXUS, and MATRIX series products, specifically version 3.08.02. This flaw allows unauthorized access to onboard project backup bundles, potentially revealing sensitive user credentials. With a CVSS score of 7.5, it is easily exploitable over the network without authentication, leading to a high confidentiality impact. While not yet in CISA's KEV catalog, a public exploit (EDB-52224) exists, though there is currently minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-12_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-2_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-256_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-96_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:nexus-2128_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.