← back
CVE-2024-48849highCWE-1385

Authentication and Authorization Issues

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.8epss 0.9%
from disclosure to weapon72 days
Published on NVDJan 29
1st PoC+72d
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

FLXEON fails to properly validate the origin of WebSocket connections, allowing attackers to make unauthorized HTTPS requests by exploiting weak session management. This could let someone perform actions on behalf of a legitimate user without their knowledge.

Technical detail

A missing Origin validation vulnerability in FLXEON's WebSocket implementation allows cross-site request forgery (CSRF) attacks. The insufficient session management mechanism fails to verify the legitimacy of connection origins, enabling an attacker to trigger unauthorized HTTPS requests in the context of an authenticated user's session. Affected versions: up to 9.3.4.

Summary generated and translated by AI from the official description.
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
ABB · FLXEON
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.