CRITICAL🇵🇱 Wersja polska

CVE-2024-48839

CVSS 9.3v4.0pub. 2024-12-05upd. 2025-02-27

Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

🤖 AI Analysis
How it works

The vulnerability stems from lack of proper input validation of data supplied over the network to control software components (CWE-94 — Code Injection). An attacker can send specially crafted input data that will be improperly processed by the application and result in arbitrary code execution on the device side. The attack vector is network-based (AV:N), requires no authentication (PR:N) or user interaction (UI:N), which means the attack can be conducted fully remotely without any prior privileges.

Impact

An attacker can gain full control of the device by executing arbitrary code with its privileges, which may lead to breach of confidentiality and integrity of processed data as well as disruption of building management systems or industrial automation operations.

Mitigation & patch

Apply patches available from the manufacturer according to references (ABB documentation with identifier 9AKK108469A7497). It is recommended to deploy updates as soon as possible and restrict network access to devices only from trusted hosts until the patch is applied.

Who is affected

ABB ASPECT - Enterprise v3.08.02, ABB NEXUS Series v3.08.02, ABB MATRIX Series v3.08.02

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Abb Aspect Ent 12

    HW
    Abb
    all versions
  • Abb Aspect Ent 12 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Aspect Ent 2

    HW
    Abb
    all versions
  • Abb Aspect Ent 256

    HW
    Abb
    all versions
  • Abb Aspect Ent 256 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Aspect Ent 2 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Aspect Ent 96

    HW
    Abb
    all versions
  • Abb Aspect Ent 96 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Matrix 11

    HW
    Abb
    all versions
  • Abb Matrix 11 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Matrix 216

    HW
    Abb
    all versions
  • Abb Matrix 216 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Matrix 232

    HW
    Abb
    all versions
  • Abb Matrix 232 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Matrix 264

    HW
    Abb
    all versions
  • Abb Matrix 264 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Matrix 296

    HW
    Abb
    all versions
  • Abb Matrix 296 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Nexus 2128

    HW
    Abb
    all versions
  • Abb Nexus 2128 A

    HW
    Abb
    all versions
  • Abb Nexus 2128 A Firmware

    OS
    Abb
    < 3.08.03
  • Abb Nexus 2128 F

    HW
    Abb
    all versions
  • Abb Nexus 2128 F Firmware

    OS
    Abb
    < 3.08.03
  • Abb Nexus 2128 Firmware

    OS
    Abb
    < 3.08.03
  • Abb Nexus 2128 G

    HW
    Abb
    all versions
  • Abb Nexus 2128 G Firmware

    OS
    Abb
    < 3.08.03
  • Abb Nexus 264

    HW
    Abb
    all versions
  • Abb Nexus 264 A

    HW
    Abb
    all versions
  • Abb Nexus 264 A Firmware

    OS
    Abb
    < 3.08.03
  • Abb Nexus 264 F

    HW
    Abb
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-51547CRITICAL9.3PL ✓same product

Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX

CVE-2024-51545CRITICAL9.3PL ✓same product

Enumeracja nazw użytkowników w ABB ASPECT, NEXUS i MATRIX Series

CVE-2024-11317CRITICAL9.3PL ✓same product

Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika

CVE-2024-48840CRITICAL9.3PL ✓same product

RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX

CVE-2024-48845CRITICAL9.3PL ✓same product

Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX