CRITICAL🇵🇱 Wersja polska

CVE-2024-6298

CVSS 9.4v4.0pub. 2024-07-05upd. 2024-12-05

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely

🤖 AI Analysis
How it works

An error in data input classification or validation (CWE-1287) in the WEB server of ABB ASPECT products allows an attacker to gain unauthorized access to system files without authentication. By exploiting this vulnerability, an attacker operating in the same network segment can upload or read files in a way that enables remote code execution (RCE) on the vulnerable device.

Impact

An attacker can remotely execute arbitrary code on the device without possessing any privileges, gaining full control over the building management system and potentially over the associated network infrastructure.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Detailed information about updates is available in the ABB document with identifier 9AKK108469A7497. Additionally, it is recommended to restrict network access to the WEB interface exclusively to trusted network segments and implement network segmentation for ASPECT devices.

Who is affected

ABB ASPECT - Enterprise version v3.08.01, ABB NEXUS Series version v3.08.01, ABB MATRIX Series version v3.08.01 (including products Aspect-Ent-12, Aspect-Ent-2, Aspect-Ent-256 and their firmware).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:I/V:C/RE:H/U:Red
  • Abb Aspect Ent 12

    HW
    Abb
    all versions
  • Abb Aspect Ent 12 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Aspect Ent 2

    HW
    Abb
    all versions
  • Abb Aspect Ent 256

    HW
    Abb
    all versions
  • Abb Aspect Ent 256 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Aspect Ent 2 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Aspect Ent 96

    HW
    Abb
    all versions
  • Abb Aspect Ent 96 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Matrix 11

    HW
    Abb
    all versions
  • Abb Matrix 11 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Matrix 216

    HW
    Abb
    all versions
  • Abb Matrix 216 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Matrix 232

    HW
    Abb
    all versions
  • Abb Matrix 232 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Matrix 264

    HW
    Abb
    all versions
  • Abb Matrix 264 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Matrix 296

    HW
    Abb
    all versions
  • Abb Matrix 296 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Nexus 2128

    HW
    Abb
    all versions
  • Abb Nexus 2128 A

    HW
    Abb
    all versions
  • Abb Nexus 2128 A Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Nexus 2128 F

    HW
    Abb
    all versions
  • Abb Nexus 2128 F Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Nexus 2128 Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Nexus 2128 G

    HW
    Abb
    all versions
  • Abb Nexus 2128 G Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Nexus 264

    HW
    Abb
    all versions
  • Abb Nexus 264 A

    HW
    Abb
    all versions
  • Abb Nexus 264 A Firmware

    OS
    Abb
    ≤ 3.08.01
  • Abb Nexus 264 F

    HW
    Abb
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-51547CRITICAL9.3PL ✓same product

Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX

CVE-2024-48845CRITICAL9.3PL ✓same product

Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX

CVE-2024-11317CRITICAL9.3PL ✓same product

Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika

CVE-2024-48839CRITICAL9.3PL ✓same product

RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX

CVE-2024-48840CRITICAL9.3PL ✓same product

RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX