Vulnerability Description
Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abb | Aspect-Ent-2 Firmware | < 3.08.03 |
| Abb | Aspect-Ent-2 | - |
| Abb | Aspect-Ent-256 Firmware | < 3.08.03 |
| Abb | Aspect-Ent-256 | - |
| Abb | Aspect-Ent-96 Firmware | < 3.08.03 |
| Abb | Aspect-Ent-96 | - |
| Abb | Nexus-2128 Firmware | < 3.08.03 |
| Abb | Nexus-2128 | - |
| Abb | Nexus-2128-A Firmware | < 3.08.03 |
| Abb | Nexus-2128-A | - |
| Abb | Nexus-2128-F Firmware | < 3.08.03 |
| Abb | Nexus-2128-F | - |
| Abb | Nexus-2128-G Firmware | < 3.08.03 |
| Abb | Nexus-2128-G | - |
| Abb | Nexus-264 Firmware | < 3.08.03 |
| Abb | Nexus-264 | - |
| Abb | Nexus-264-A Firmware | < 3.08.03 |
| Abb | Nexus-264-A | - |
| Abb | Nexus-264-G Firmware | < 3.08.03 |
| Abb | Nexus-264-G | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-11317?
CVE-2024-11317 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product. Affected products: ABB ASPECT - Enterpr...
How severe is CVE-2024-11317?
CVE-2024-11317 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-11317?
Check the references section above for vendor advisories and patch information. Affected products include: Abb Aspect-Ent-2 Firmware, Abb Aspect-Ent-2, Abb Aspect-Ent-256 Firmware, Abb Aspect-Ent-256, Abb Aspect-Ent-96 Firmware.