CVE-2024-48844
HIGHABB ASPECT, NEXUS, and MATRIX Firmware < 3.08.03 - Denial of Service
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48844. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an off-by-one error in ABB Cylon Aspect's escDevicesUpdate.php script, where a maliciously crafted rowCount POST parameter can trigger an out-of-bounds array access, leading to a denial-of-service (DoS) condition.
Description
Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
Exploits (1)
This exploit demonstrates an off-by-one error in ABB Cylon Aspect's escDevicesUpdate.php script, where a maliciously crafted rowCount POST parameter can trigger an out-of-bounds array access, leading to a denial-of-service (DoS) condition.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H