CVE-2024-6298
published 2024-07-05CVE-2024-6298: Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary…
PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
19.01%
97.0th percentile
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to execute arbitrary code remotely
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | aspect-ent-12_firmware | <= 3.08.01 | — |
| abb | aspect-ent-256_firmware | <= 3.08.01 | — |
| abb | aspect-ent-2_firmware | <= 3.08.01 | — |
| abb | aspect-ent-96_firmware | <= 3.08.01 | — |
| abb | aspect-enterprise | <= 3.08.01 | — |
| abb | matrix-11_firmware | <= 3.08.01 | — |
| abb | matrix-216_firmware | <= 3.08.01 | — |
| abb | matrix-232_firmware | <= 3.08.01 | — |
| abb | matrix-264_firmware | <= 3.08.01 | — |
| abb | matrix-296_firmware | <= 3.08.01 | — |
| abb | matrix_series | <= 3.08.01 | — |
| abb | nexus-2128-a_firmware | <= 3.08.01 | — |
| abb | nexus-2128-f_firmware | <= 3.08.01 | — |
| abb | nexus-2128-g_firmware | <= 3.08.01 | — |
| abb | nexus-2128_firmware | <= 3.08.01 | — |
| abb | nexus-264-a_firmware | <= 3.08.01 | — |
| abb | nexus-264-f_firmware | <= 3.08.01 | — |
| abb | nexus-264-g_firmware | <= 3.08.01 | — |
| abb | nexus-264_firmware | <= 3.08.01 | — |
| abb | nexus-3-2128_firmware | <= 3.08.01 | — |
| abb | nexus-3-264_firmware | <= 3.08.01 | — |
| abb | nexus_series | <= 3.08.01 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP POST requests to /bigUpload.php with query parameters 'action=upload', 'action=finish', and a 'key' parameter, which are characteristic of the multi-step exploit chain. ↗
- →Detect path traversal sequences in the 'name' POST parameter of bigUpload.php targeting the web root at /home/MIX_CMIX/htmlroot/. ↗
- →Alert on GET requests to newly created .php files in the web root (e.g., /ZSL.php) with query parameters used as command execution arguments (e.g., ?j=id), indicating successful webshell deployment. ↗
- →The exploit runs as www-data (uid=33); monitor for unexpected process execution or file creation by the www-data user on ABB ASPECT/NEXUS/MATRIX devices. ↗
- ·The exploit targets ABB ASPECT-Enterprise, NEXUS Series, MATRIX-2 Series, and ASPECT-Studio all at firmware/software version 3.08.01; detections should be scoped to these specific product lines. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:I/V:C/RE:H/U:Red
vulncheck9.4CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w76v-3936-3wp3: Improper Input Validation vulnerability in ABB ASPECT-Enterprise on Linux, ABB NEXUS Series on Linux, ABB MATRIX Series on Linux allows Remote Code In
ghsa_unreviewed·2024-07-05
CVE-2024-6298 [CRITICAL] CWE-1287 GHSA-w76v-3936-3wp3: Improper Input Validation vulnerability in ABB ASPECT-Enterprise on Linux, ABB NEXUS Series on Linux, ABB MATRIX Series on Linux allows Remote Code In
Improper Input Validation vulnerability in ABB ASPECT-Enterprise on Linux, ABB NEXUS Series on Linux, ABB MATRIX Series on Linux allows Remote Code Inclusion.This issue affects ASPECT-Enterprise: through 3.08.01; NEXUS Series: through 3.08.01; MATRIX Series: through 3.08.01.
VulnCheck
abb aspect-ent-12_firmware Improper Validation of Specified Type of Input
vulncheck·2024·CVSS 9.4
CVE-2024-6298 [CRITICAL] abb aspect-ent-12_firmware Improper Validation of Specified Type of Input
abb aspect-ent-12_firmware Improper Validation of Specified Type of Input
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to execute arbitrary code remotely
Affected: abb aspect-ent-12_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2025-02-02&host_type=src&vulnerability=cve-2024-6298; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2025-02-21&host_type=src&vulnerability=cve-2024-6298; https://dashboard.shadowserver.org/statistics/honeypot/vulnerab
CISA ICS
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
cisa_ics·2025-01-07·CVSS 8.7
[HIGH] ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
ICS Advisory
##
ABB ASPECT-Enterprise, NEXUS, and MATRIX Series Products
Release DateJanuary 07, 2025
Alert CodeICSA-25-007-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: ASPECT-Enterprise, NEXUS, and MATRIX series
- Vulnerabilities: Files or Directories Accessible to External Parties, Improper Validation of Specified Type of Input, Cleartext Transmission of Sensitive Information, Cross-site Scripting, Server-Side Request Forgery (SSRF), Improper Neutralization of Special Elements in Data Query Logic, Allocation of Resources Without Limits or Throttling, Weak Password Requirements, Cr
No detection rules found.
No writeups or analysis indexed.
2024-07-05
Published
Exploited in the wild