PT-2024-6688 · Abb · Matrix Series+2

Published

2024-04-21

·

Updated

2025-08-18

·

CVE-2024-6298

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ABB ASPECT Enterprise versions through 3.08.01 ABB NEXUS Series versions through 3.08.01 ABB MATRIX Series versions through 3.08.01
Description: An improper input validation vulnerability exists in the uploadFile() function within the bigUpload.php script of ABB ASPECT Enterprise, NEXUS Series, and MATRIX Series embedded network building management controllers. This vulnerability allows for directory traversal due to insufficient input validation, potentially leading to remote code inclusion. Successful exploitation could allow a remote attacker to gain unauthorized access to the device, write arbitrary files, and execute arbitrary code.
Recommendations: ABB ASPECT Enterprise versions prior to 3.08.01 ABB NEXUS Series versions prior to 3.08.01 ABB MATRIX Series versions prior to 3.08.01

Exploit

Fix

Path traversal

Relative Path Traversal

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-07895
CVE-2024-6298

Affected Products

Aspect-Enterprise
Matrix Series
Nexus Series