CVE-2024-51546

HIGH

ABB ASPECT Enterprise, NEXUS Series, MATRIX Series <3.08.02 - Credentials Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-51546. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit details an information leakage vulnerability in ABB Cylon Aspect 3.08.02, where sensitive credentials are transmitted and stored in cleartext within HTTP cookies. The base64-encoded 'authdata' field in the 'globals' cookie parameter exposes user credentials, allowing remote attackers to intercept them via man-in-the-middle attacks.

Description

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · texthardwaremultiple
https://www.exploit-db.com/exploits/52224

The exploit details an information leakage vulnerability in ABB Cylon Aspect 3.08.02, where sensitive credentials are transmitted and stored in cleartext within HTTP cookies. The base64-encoded 'authdata' field in the 'globals' cookie parameter exposes user credentials, allowing remote attackers to intercept them via man-in-the-middle attacks.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ABB Cylon Aspect <=3.08.02
No auth needed
Prerequisites: Network access to intercept HTTP traffic · Victim must be authenticated to generate the vulnerable cookie
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.1707
EPSS Percentile 95.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-522 CWE-1287
Status published
Products (19)
abb/aspect-ent-12_firmware < 3.08.03
abb/aspect-ent-256_firmware < 3.08.03
abb/aspect-ent-2_firmware < 3.08.03
abb/aspect-ent-96_firmware < 3.08.03
abb/matrix-11_firmware < 3.08.03
abb/matrix-216_firmware < 3.08.03
abb/matrix-232_firmware < 3.08.03
abb/matrix-264_firmware < 3.08.03
abb/matrix-296_firmware < 3.08.03
abb/nexus-2128-a_firmware < 3.08.03
... and 9 more
Published Dec 05, 2024
Tracked Since Feb 18, 2026