PT-2025-22533 · Unknown · Matrix Series+2

Published

2025-05-22

·

Updated

2025-05-28

·

CVE-2024-13946

CVSS v3.1

6.8

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions ASPECT-Enterprise versions through 3.* NEXUS Series versions through 3.* MATRIX Series versions through 3.*
Description The issue is related to DLL's not being digitally signed when loaded in ASPECT's configuration toolset. This exposes the application to binary planting during device commissioning.
Recommendations For ASPECT-Enterprise versions through 3., consider implementing digital signatures for DLL's to prevent binary planting. For NEXUS Series versions through 3., restrict access to the configuration toolset during device commissioning to minimize the risk of exploitation. For MATRIX Series versions through 3.*, avoid using the configuration toolset until a fix is available that includes digital signatures for DLL's. As a temporary workaround, consider disabling the loading of unsigned DLL's in the configuration toolset until a patch is available.

Exploit

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13946

Affected Products

Aspect-Enterprise
Matrix Series
Nexus Series