PT-2024-9182 · Abb · Matrix Series+2
Published
2024-12-05
·
Updated
2024-12-05
·
CVE-2024-51548
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ABB ASPECT - Enterprise version 3.08.02
NEXUS Series version 3.08.02
MATRIX Series version 3.08.02
Description:
The issue is related to a file upload vulnerability that allows the upload of malicious scripts. This can be exploited by a remote attacker to inject malicious code.
Recommendations:
For ABB ASPECT - Enterprise version 3.08.02, consider disabling file upload functionality until a patch is available.
For NEXUS Series version 3.08.02, restrict access to file upload features to minimize the risk of exploitation.
For MATRIX Series version 3.08.02, avoid using the file upload feature in the affected products until the issue is resolved.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abb Aspect
Matrix Series
Nexus Series