PT-2024-9182 · Abb · Matrix Series+2

Published

2024-12-05

·

Updated

2024-12-05

·

CVE-2024-51548

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ABB ASPECT - Enterprise version 3.08.02 NEXUS Series version 3.08.02 MATRIX Series version 3.08.02
Description: The issue is related to a file upload vulnerability that allows the upload of malicious scripts. This can be exploited by a remote attacker to inject malicious code.
Recommendations: For ABB ASPECT - Enterprise version 3.08.02, consider disabling file upload functionality until a patch is available. For NEXUS Series version 3.08.02, restrict access to file upload features to minimize the risk of exploitation. For MATRIX Series version 3.08.02, avoid using the file upload feature in the affected products until the issue is resolved.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-10869
CVE-2024-51548

Affected Products

Abb Aspect
Matrix Series
Nexus Series