CVE-2024-51546
HIGHABB ASPECT Enterprise, NEXUS Series, MATRIX Series <3.08.02 - Credentials Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-51546. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit details an information leakage vulnerability in ABB Cylon Aspect 3.08.02, where sensitive credentials are transmitted and stored in cleartext within HTTP cookies. The base64-encoded 'authdata' field in the 'globals' cookie parameter exposes user credentials, allowing remote attackers to intercept them via man-in-the-middle attacks.
Description
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
Exploits (1)
The exploit details an information leakage vulnerability in ABB Cylon Aspect 3.08.02, where sensitive credentials are transmitted and stored in cleartext within HTTP cookies. The base64-encoded 'authdata' field in the 'globals' cookie parameter exposes user credentials, allowing remote attackers to intercept them via man-in-the-middle attacks.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N