PT-2024-9241 · Abb · Matrix Series+2

Published

2024-12-05

·

Updated

2024-12-09

·

CVE-2024-51549

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions: ABB ASPECT - Enterprise version 3.08.02 NEXUS Series version 3.08.02 MATRIX Series version 3.08.02
Description: The issue is related to an absolute file traversal vulnerability, which allows access and modification of unintended resources. This is due to incorrect restriction of directory path names in the software of embedded network controllers for building management. Exploitation of this issue can allow a remote attacker to gain unauthorized access to resources and modify them.
Recommendations: For ABB ASPECT - Enterprise version 3.08.02, consider restricting access to sensitive resources until a patch is available. For NEXUS Series version 3.08.02, avoid using vulnerable functions that allow file traversal until the issue is resolved. For MATRIX Series version 3.08.02, limit the modification of resources to authorized personnel only as a temporary mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-10929
CVE-2024-51549

Affected Products

Abb Aspect
Matrix Series
Nexus Series