PT-2024-6689 · Abb · Matrix Series+2
Published
2024-04-21
·
Updated
2025-08-18
·
CVE-2024-6209
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ABB ASPECT - Enterprise versions 3.08.01
ABB NEXUS Series versions 3.08.01
ABB MATRIX Series versions 3.08.01
Description:
An unauthorized file access issue exists in the WEB Server of ABB ASPECT - Enterprise, NEXUS Series, and MATRIX Series. This allows an attacker to access unauthorized files. The vulnerability is related to the use of files and directories accessible to external parties. Exploitation may allow a remote attacker to gain unauthorized access to the device and delete arbitrary files. The vulnerability is a pre-authentication directory traversal and file deletion issue, rather than a file read issue. A remote code execution (RCE) vulnerability also exists in the same file, pre-authentication.
Recommendations:
ABB ASPECT - Enterprise version 3.08.01: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
ABB NEXUS Series version 3.08.01: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
ABB MATRIX Series version 3.08.01: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abb Aspect
Matrix Series
Nexus Series