CVE-2024-48849
published 2025-01-29CVE-2024-48849: Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue…
PriorityP259critical9.4CVSS 3.1
AVNACLPRNUINSUCLIHAH
EXPLOIT
EPSS
0.89%
55.4th percentile
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | flxeon | <= <= 9.3.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated WebSocket connections to FLXEON controllers; the vulnerability allows unauthorized HTTPS requests due to missing origin validation and insufficient session management in wsConnect.js. ↗
- →Detect use of 'websocat' tool with --insecure flag and buffer-size 251 targeting FLXEON devices, which is the PoC exploit delivery mechanism for this CVE. ↗
- →Alert on log entries containing 'ws connect' from node process on FLXEON devices, which indicates an active WebSocket connection attempt that may be exploitation-related. ↗
- →Monitor access to split log files under /usr/local/aam/var/ (xaa, xab, xac, xad), which are artifacts of post-exploitation log exfiltration activity on FLXEON devices. ↗
- →Detect JSONRPC messages sent over WebSocket to FLXEON controllers containing START_SERVICE or STOP_SERVICE commands without prior authentication, indicative of exploitation of CVE-2024-48849. ↗
- ·The vulnerability is only exploitable if the FLXEON device is accessible on the network segment or exposed directly to the internet; network-isolated deployments have reduced risk. ↗
- ·All FLXEON controller series (FBXi, FBVi, FBTi, CBXi) running firmware 9.3.4 and prior are affected; detections should cover all four product lines. ↗
CVSS provenance
nvdv3.19.4CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r2c5-m74g-gvx4: Missing Origin Validation in WebSockets vulnerability in FLXEON
ghsa_unreviewed·2025-01-29
CVE-2024-48849 [HIGH] CWE-1385 GHSA-r2c5-m74g-gvx4: Missing Origin Validation in WebSockets vulnerability in FLXEON
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
CISA ICS
ABB FLXEON Controllers
cisa_ics·2025-02-20·CVSS 10.0
[CRITICAL] ABB FLXEON Controllers
ICS Advisory
##
ABB FLXEON Controllers
Release DateFebruary 20, 2025
Alert CodeICSA-25-051-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: FLXEON Controllers
- Vulnerabilities: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion'), Missing Origin Validation in WebSockets, Insertion of Sensitive Information into Log File
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to send unauthorized HTTPS requests, access sensitive information from HTTPS responses, or use network access to execute re
No detection rules found.
No writeups or analysis indexed.
2025-01-29
Published