CVE-2024-48846

EUVD-2024-43165
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. 
Affected products:


ABB ASPECT - Enterprise v3.08.02; 
NEXUS Series v3.08.02; 
MATRIX Series v3.08.02
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
ABBCNA
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
abbaspect-ent-2_firmware
𝑥
< 3.08.03
abbaspect-ent-256_firmware
𝑥
< 3.08.03
abbaspect-ent-96_firmware
𝑥
< 3.08.03
abbnexus-2128_firmware
𝑥
< 3.08.03
abbnexus-2128-a_firmware
𝑥
< 3.08.03
abbnexus-2128-f_firmware
𝑥
< 3.08.03
abbnexus-2128-g_firmware
𝑥
< 3.08.03
abbnexus-264_firmware
𝑥
< 3.08.03
abbnexus-264-a_firmware
𝑥
< 3.08.03
abbnexus-264-g_firmware
𝑥
< 3.08.03
abbnexus-3-2128_firmware
𝑥
< 3.08.03
abbaspect-ent-12_firmware
𝑥
< 3.08.03
abbnexus-264-f_firmware
𝑥
< 3.08.03
abbnexus-3-264_firmware
𝑥
< 3.08.03
abbmatrix-11_firmware
𝑥
< 3.08.03
abbmatrix-216_firmware
𝑥
< 3.08.03
abbmatrix-232_firmware
𝑥
< 3.08.03
abbmatrix-264_firmware
𝑥
< 3.08.03
abbmatrix-296_firmware
𝑥
< 3.08.03
𝑥
= Vulnerable software versions