PT-2024-33129 · Abb · Abb Drive Composer

·

CVE-2024-48510

·

Published

2024-11-13

·

Updated

2025-07-19

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DotNetZip versions 1.16.0 and earlier ABB Drive Composer versions prior to 2.9.1
Description The issue allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component. This affects products that are no longer supported by the maintainer. The problem has been reportedly exploited in real-world attacks.
Recommendations For DotNetZip versions 1.16.0 and earlier, consider disabling the ZipEntry.Extract.cs component until a patch is available. For ABB Drive Composer versions prior to 2.9.1, update to version 2.9.1 for protection.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00104
CVE-2024-48510
GHSA-XHG6-9J5J-W4VF

Affected Products

Abb Drive Composer