CVE-2024-51550
published 2024-12-05CVE-2024-51550: Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected products: ABB…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
1.82%
76.4th percentile
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | aspect-ent-12_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-256_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-2_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-ent-96_firmware | < 3.08.03 | 3.08.03 |
| abb | aspect-enterprise | <= 3.08.02 | — |
| abb | matrix-11_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-216_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-232_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-264_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix-296_firmware | < 3.08.03 | 3.08.03 |
| abb | matrix_series | <= 3.08.02 | — |
| abb | nexus-2128-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-a_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-f_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264-g_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-264_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-2128_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus-3-264_firmware | < 3.08.03 | 3.08.03 |
| abb | nexus_series | <= 3.08.02 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect POST requests to /bbmdUpdate.php containing shell metacharacters (semicolons, hash/comment characters) in the hexMask or NAThexMask parameters, indicative of OS command injection. ↗
- →Monitor for POST requests to /bbmdUpdate.php with parameters rowCount, ip1/ip2, port1/port2, hexMask1/hexMask2, remove1/remove2 — the attack surface for the BBMD update injection vector. ↗
- →Monitor for POST requests to /bbmdUpdate.php with parameters rowCountNAT, NATip, NATport, NAThexMask, NATremove — the NAT variant of the injection vector. ↗
- →Flag time-based blind command injection attempts: a `sleep` command injected into hexMask or NAThexMask fields causing a ~17-second response delay is a strong indicator of exploitation. ↗
- ·The exploit uses an authenticated session (PHPSESSID cookie), meaning the attacker must already possess a valid session token. Detection should also cover credential abuse or session hijacking as a precursor. ↗
- ·Affected versions are specifically ABB ASPECT-Enterprise, NEXUS Series, MATRIX Series, and ASPECT-Studio at firmware/software version 3.08.02. Detections should be scoped to these devices. ↗
- ·The vulnerability is a data validation/sanitization failure — unsanitized POST parameters are passed directly to OS-level commands. Any parameter accepting hex mask or IP/port values in bbmdUpdate.php should be treated as untrusted. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-78pr-m5p7-52qj: Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device
ghsa_unreviewed·2024-12-05
CVE-2024-51550 [CRITICAL] CWE-1287 GHSA-78pr-m5p7-52qj: Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
CISA ICS
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
cisa_ics·2025-01-07·CVSS 8.7
[HIGH] ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
ICS Advisory
##
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
Release DateJanuary 07, 2025
Alert CodeICSA-25-007-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: ASPECT-Enterprise, NEXUS, and MATRIX series
- Vulnerabilities: Files or Directories Accessible to External Parties, Improper Validation of Specified Type of Input, Cleartext Transmission of Sensitive Information, Cross-site Scripting, Server-Side Request Forgery (SSRF), Improper Neutralization of Special Elements in Data Query Logic, Allocation of Resources Without Limits or Throttling, Weak Password Requirements, Cr
No detection rules found.
No writeups or analysis indexed.
2024-12-05
Published