CVE-2024-6516
Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- Affected products
- Abb Aspect, Matrix Series, Nexus Series
- Abb aspect-ent-2 Firmware
- < 3.08.03
- CVSS 4.0
- 9.3 CRITICAL
- CVSS 3.1
- 9.0 CRITICAL
- EPSS
- 1.1% (63th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2024-12-05
CVE-2024-6516 at NVD
7 known exploits for CVE-2024-6516
Proof-of-concept code and exploit modules indexed by Sploitus
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 (licenseUpload.php) Stored Cross-Site Scripting
ABB Cylon Aspect 3.08.02 bbmdUpdate.php Remote Code Execution Vulnerability
ABB Cylon Aspect 3.08.02 (WatchDogServlet) Authenticated Reflected XSS