PT-2025-22533 · Unknown · Matrix Series+2
Published
2025-05-22
·
Updated
2025-05-28
·
CVE-2024-13946
CVSS v3.1
6.8
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
ASPECT-Enterprise versions through 3.*
NEXUS Series versions through 3.*
MATRIX Series versions through 3.*
Description
The issue is related to DLL's not being digitally signed when loaded in ASPECT's configuration toolset. This exposes the application to binary planting during device commissioning.
Recommendations
For ASPECT-Enterprise versions through 3., consider implementing digital signatures for DLL's to prevent binary planting.
For NEXUS Series versions through 3., restrict access to the configuration toolset during device commissioning to minimize the risk of exploitation.
For MATRIX Series versions through 3.*, avoid using the configuration toolset until a fix is available that includes digital signatures for DLL's.
As a temporary workaround, consider disabling the loading of unsigned DLL's in the configuration toolset until a patch is available.
Exploit
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aspect-Enterprise
Matrix Series
Nexus Series