RULE(RULE ID:338882)

Rule General Information
Release Date: 2025-05-07
Rule Name: ABB Cylon Aspect 3.08.02 Stored Cross Site Scripting Vulnerability (CVE-2024-6516)
Severity:
CVE ID:
Rule Protection Details
Description: Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://search.abb.com/library/Download.aspx
Solutions
Refer to the announcement or patch by the vendor: https://search.abb.com/library/Download.aspx