CVE-2024-51546

HIGH
Published Dec 5, 2024 Modified Apr 10, 2025 CWE-1287 CWE-522

Description

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Is your site exposed to CVE-2024-51546?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weakness Type (CWE)

CWE-1287 CWE-1287
CWE-522 CWE-522

Affected Products

Vendor Product
abb aspect-ent-12_firmware
abb aspect-ent-12
abb aspect-ent-2
abb aspect-ent-2_firmware
abb aspect-ent-256
abb aspect-ent-256_firmware
abb aspect-ent-96
abb aspect-ent-96_firmware
abb nexus-2128
abb nexus-2128_firmware
abb nexus-2128-a
abb nexus-2128-a_firmware
abb nexus-2128-f
abb nexus-2128-f_firmware
abb nexus-2128-g
abb nexus-2128-g_firmware
abb nexus-264
abb nexus-264_firmware
abb nexus-264-a
abb nexus-264-a_firmware
abb nexus-264-f
abb nexus-264-f_firmware
abb nexus-264-g
abb nexus-264-g_firmware
abb nexus-3-2128
abb nexus-3-2128_firmware
abb nexus-3-264_firmware
abb nexus-3-264
abb matrix-11_firmware
abb matrix-11
abb matrix-216_firmware
abb matrix-216
abb matrix-232_firmware
abb matrix-232
abb matrix-264_firmware
abb matrix-264
abb matrix-296_firmware
abb matrix-296

References

Frequently Asked Questions

What is CVE-2024-51546? +
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02 It has a CVSS v3.1 base score of 7.5 (HIGH).
How severe is CVE-2024-51546? +
CVE-2024-51546 has a CVSS v3.1 score of 7.5 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-51546? +
CVE-2024-51546 affects products from abb, specifically: aspect-ent-12, aspect-ent-12_firmware, aspect-ent-2, aspect-ent-256, aspect-ent-256_firmware, aspect-ent-2_firmware, aspect-ent-96, aspect-ent-96_firmware, matrix-11, matrix-11_firmware, matrix-216, matrix-216_firmware, matrix-232, matrix-232_firmware, matrix-264, matrix-264_firmware, matrix-296, matrix-296_firmware, nexus-2128, nexus-2128-a, nexus-2128-a_firmware, nexus-2128-f, nexus-2128-f_firmware, nexus-2128-g, nexus-2128-g_firmware, nexus-2128_firmware, nexus-264, nexus-264-a, nexus-264-a_firmware, nexus-264-f, nexus-264-f_firmware, nexus-264-g, nexus-264-g_firmware, nexus-264_firmware, nexus-3-2128, nexus-3-2128_firmware, nexus-3-264, nexus-3-264_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-51546? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-51546 — free, no signup required.