CVE-2024-6515

Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of  unintended credentails exposure.
Affected products:


ABB ASPECT - Enterprise v3.08.02; 
NEXUS Series v3.08.02; 
MATRIX Series v3.08.02
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.6 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
ABBCNA
9.6 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
abbaspect-ent-2_firmware
𝑥
< 3.08.03
abbaspect-ent-256_firmware
𝑥
< 3.08.03
abbaspect-ent-96_firmware
𝑥
< 3.08.03
abbnexus-2128_firmware
𝑥
< 3.08.03
abbnexus-2128-a_firmware
𝑥
< 3.08.03
abbnexus-2128-f_firmware
𝑥
< 3.08.03
abbnexus-2128-g_firmware
𝑥
< 3.08.03
abbnexus-264_firmware
𝑥
< 3.08.03
abbnexus-264-a_firmware
𝑥
< 3.08.03
abbnexus-264-g_firmware
𝑥
< 3.08.03
abbnexus-3-2128_firmware
𝑥
< 3.08.03
abbaspect-ent-12_firmware
𝑥
< 3.08.03
abbnexus-264-f_firmware
𝑥
< 3.08.03
abbnexus-3-264_firmware
𝑥
< 3.08.03
abbmatrix-11_firmware
𝑥
< 3.08.03
abbmatrix-216_firmware
𝑥
< 3.08.03
abbmatrix-232_firmware
𝑥
< 3.08.03
abbmatrix-264_firmware
𝑥
< 3.08.03
abbmatrix-296_firmware
𝑥
< 3.08.03
𝑥
= Vulnerable software versions