First published: Thu Dec 05 2024(Updated: )
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ABB ASPECT | ||
ABB NEXUS Series | ||
ABB MATRIX Series | ||
All of | ||
ABB ASPECT | <3.08.03 | |
ABB ASPECT | ||
All of | ||
ABB ASPECT | <3.08.03 | |
ABB ASPECT | ||
All of | ||
ABB ASPECT | <3.08.03 | |
ABB ASPECT | ||
All of | ||
ABB Nexus-2128-F | <3.08.03 | |
Abb Nexus-2128 Firmware | ||
All of | ||
Abb Nexus-2128-a Firmware | <3.08.03 | |
Abb Nexus-2128-a | ||
All of | ||
ABB Nexus-2128-F | <3.08.03 | |
Abb Nexus-2128-f Firmware | ||
All of | ||
Abb Nexus-2128-g | <3.08.03 | |
Abb Nexus-2128-g Firmware | ||
All of | ||
ABB Nexus-264-F | <3.08.03 | |
Abb Nexus-264 Firmware | ||
All of | ||
Abb Nexus-264 Firmware | <3.08.03 | |
Abb Nexus-264-a Firmware | ||
All of | ||
Abb Nexus-264 Firmware | <3.08.03 | |
Abb Nexus-264-g Firmware | ||
All of | ||
Abb Nexus-3-2128 | <3.08.03 | |
Abb Nexus-3-2128 Firmware | ||
All of | ||
ABB ASPECT | <=3.07.02 | |
ABB ASPECT | ||
All of | ||
Abb Nexus-264 Firmware | <3.08.03 | |
Abb Nexus-264-f Firmware | ||
All of | ||
Abb Nexus-3-264 | <=3.07.02 | |
Abb Nexus-3-264 Firmware | ||
All of | ||
Abb Matrix-11 | <=3.07.02 | |
Abb Matrix-11 Firmware | ||
All of | ||
Abb Matrix-216 | <=3.07.02 | |
Abb Matrix-216 Firmware | ||
All of | ||
Abb Matrix-232 | <=3.07.02 | |
Abb Matrix-232 | ||
All of | ||
ABB Matrix-264 | <=3.07.02 | |
Abb Matrix-264 Firmware | ||
All of | ||
ABB Matrix-296 | <=3.07.02 | |
ABB MATRIX-296 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48845 is considered a moderate severity vulnerability due to its potential for unauthorized access via weak password reset rules.
To fix CVE-2024-48845, implement stronger password reset rules and ensure that passwords meet complexity requirements.
CVE-2024-48845 affects ABB ASPECT - Enterprise v3.07.02, NEXUS Series v3.07.02, and MATRIX Series v3.07.02.
The risks associated with CVE-2024-48845 include unauthorized access to administrative and application functionalities due to weak passwords.
Yes, CVE-2024-48845 can be exploited remotely if an attacker can access the password reset functionality.