CVE-2024-51544
published 2024-12-05CVE-2024-51544: Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products: ABB ASPECT - Enterprise v3.08.02…
PriorityP358high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
13.52%
96.0th percentile
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | aspect-ent-12_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-256_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-2_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-96_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-enterprise | <= 3.08.02 | — |
| abb | matrix-11_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-216_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-232_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-264_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-296_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix_series | <= 3.08.02 | — |
| abb | nexus-2128-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-264_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus_series | <= 3.08.02 | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6g3p-q5xv-hq72: Service Control vulnerabilities allow access to service restart requests and vm configuration settings
ghsa_unreviewed·2024-12-05
CVE-2024-51544 [HIGH] CWE-15 GHSA-6g3p-q5xv-hq72: Service Control vulnerabilities allow access to service restart requests and vm configuration settings
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
CISA ICS
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
cisa_ics·2025-01-07·CVSS 8.7
[HIGH] ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
ICS Advisory
##
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
Release DateJanuary 07, 2025
Alert CodeICSA-25-007-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: ASPECT-Enterprise, NEXUS, and MATRIX series
- Vulnerabilities: Files or Directories Accessible to External Parties, Improper Validation of Specified Type of Input, Cleartext Transmission of Sensitive Information, Cross-site Scripting, Server-Side Request Forgery (SSRF), Improper Neutralization of Special Elements in Data Query Logic, Allocation of Resources Without Limits or Throttling, Weak Password Requirements, Cr
Suricata
ET WEB_SPECIFIC_APPS ABB Cylon Aspect 3.08.02 Arbitrary Heap Memory Configuration (CVE-2024-51544)
suricata·2025-09-30·CVSS 8.8
CVE-2024-51544 [HIGH] ET WEB_SPECIFIC_APPS ABB Cylon Aspect 3.08.02 Arbitrary Heap Memory Configuration (CVE-2024-51544)
ET WEB_SPECIFIC_APPS ABB Cylon Aspect 3.08.02 Arbitrary Heap Memory Configuration (CVE-2024-51544)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS ABB Cylon Aspect 3.08.02 Arbitrary Heap Memory Configuration (CVE-2024-51544)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:17; content:"/aspectMemory.php"; fast_pattern; http.cookie; content:"phpsessid|3d|"; nocase; startswith; http.request_body; content:"heapmin|3d|"; nocase; content:"heapmax|3d|"; nocase; content:"action|3d|"; nocase; reference:url,www.zeroscience.mk/codes/abb_aspect_mem1.txt; reference:cve,2024-51544; classtype:web-application-attack; sid:2065002; rev:2; metadata:affected_product ABB, attack_target IoT, tls_state plaintext, created_at 2025_09_30, cve CVE_2024_51544, deployme
No public exploits indexed.
No writeups or analysis indexed.
2024-12-05
Published