CVE-2024-48840
Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- Affected products
- Abb Aspect, Matrix Series, Nexus Series
- Abb aspect-ent-2 Firmware
- < 3.08.03
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2024-12-05
CVE-2024-48840 at NVD
4 known exploits for CVE-2024-48840
Proof-of-concept code and exploit modules indexed by Sploitus
ABB Cylon Aspect 3.08.02 (deployStart.php) - Unauthenticated Command Execution
ABB Cylon Aspect 3.08.02 (deployStart.php) Unauthenticated Command Execution
ABB Cylon Aspect 3.08.02 (editOverride.php) Authentication Bypass MIX Override
ABB Cylon Aspect 3.08.02 (altlogin.php) Unauthenticated Reflected XSS