First published: Wed Jan 29 2025(Updated: )
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
FLXEON | <=9.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-48849 has not been explicitly stated, but it involves a missing origin validation which can lead to unauthorized HTTPS requests.
To fix CVE-2024-48849, ensure that you update FLXEON to a version greater than 9.3.4 where the vulnerability has been addressed.
CVE-2024-48849 affects FLXEON versions up to and including 9.3.4.
CVE-2024-48849 is characterized by missing origin validation in WebSockets, leading to potential session management issues.
Yes, CVE-2024-48849 can lead to unauthorized access due to insufficient session management allowing unauthorized HTTPS requests.