CVE-2024-48851
published 2025-09-18CVE-2024-48851: Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue…
PriorityP348high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.50%
40.0th percentile
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation.
This issue affects FLXEON: through 9.3.5.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | flxeon | <= 9.3.5 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.5HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB FLXeon Controllers
cisa_ics·2025-11-06·CVSS 7.0
[HIGH] ABB FLXeon Controllers
ICS Advisory
##
ABB FLXeon Controllers
Release DateNovember 06, 2025
Alert CodeICSA-25-310-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: FBXi, FBVi, FBTi, CBXi
- Vulnerabilities: Use of Hard-coded Credentials, Improper Validation of Specified Type of Input, Use of a One-Way Hash without a Salt
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to take remote control of the product, insert and run arbitrary code, and crash the device being accessed.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following ABB FLXeon products are af
GHSA
GHSA-chxc-9v7p-7xgg: Improper Validation of Specified Type of Input vulnerability in ABB FLXEON
ghsa_unreviewed·2025-09-18
CVE-2024-48851 [HIGH] CWE-1287 GHSA-chxc-9v7p-7xgg: Improper Validation of Specified Type of Input vulnerability in ABB FLXEON
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation.
This issue affects FLXEON: through 9.3.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-18
Published