cbcvebase.

Abb Aspect-Ent-256 Firmware vulnerabilities

29 known vulnerabilities affecting abb/aspect-ent-256_firmware.

Total CVEs
29
CISA KEV
0
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH12MEDIUM2

Vulnerabilities

Page 1 of 2
CVE-2024-6298P1CRITICALCVSS 9.8ExploitedPoC≤ 3.08.012024-07-05
CVE-2024-6298 [CRITICAL] CWE-1287 CVE-2024-6298: Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
nvd
CVE-2024-48839P2CRITICALCVSS 9.8PoCfixed in 3.08.032024-12-05
CVE-2024-48839 [CRITICAL] CWE-94 CVE-2024-48839: Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPE Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-48840P2CRITICALCVSS 9.8PoCfixed in 3.08.032024-12-05
CVE-2024-48840 [CRITICAL] CWE-94 CVE-2024-48840: Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-6209P2HIGHCVSS 7.5PoC≤ 3.08.012024-07-05
CVE-2024-6209 [HIGH] CWE-552 CVE-2024-6209: Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
nvd
CVE-2024-48845P2CRITICALCVSS 9.8PoCfixed in 3.08.032024-12-05
CVE-2024-48845 [CRITICAL] CWE-521 CVE-2024-48845: Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of wea Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
nvd
CVE-2024-11317P2CRITICALCVSS 10.0PoCfixed in 3.08.032024-12-05
CVE-2024-11317 [CRITICAL] CWE-384 CVE-2024-11317: Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login pr Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-51550P2CRITICALCVSS 9.8PoCfixed in 3.08.032024-12-05
CVE-2024-51550 [CRITICAL] CWE-1287 CVE-2024-51550: Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized dat Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-4007P3HIGHCVSS 8.8PoCfixed in 3.07.022024-07-01
CVE-2024-4007 [HIGH] CWE-1392 CVE-2024-4007: Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
nvd
CVE-2024-51546P3HIGHCVSS 7.5PoCfixed in 3.08.032024-12-05
CVE-2024-51546 [HIGH] CWE-1287 CVE-2024-51546: Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected p Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-48846P3HIGHCVSS 7.3PoCfixed in 3.08.032024-12-05
CVE-2024-48846 [HIGH] CWE-352 CVE-2024-48846: Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-51551P2CRITICALCVSS 10.0≤ 3.07.022024-12-05
CVE-2024-51551 [CRITICAL] CWE-1287 CVE-2024-51551: Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly av Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
nvd
CVE-2024-51544P3HIGHCVSS 8.2fixed in 3.08.032024-12-05
CVE-2024-51544 [HIGH] CWE-15 CVE-2024-51544: Service Control vulnerabilities allow access to service restart requests and vm configuration settin Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-48844P3MEDIUMCVSS 6.5PoCfixed in 3.08.032024-12-05
CVE-2024-48844 [MEDIUM] CWE-770 CVE-2024-48844: Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-6516P3MEDIUMCVSS 6.1PoCfixed in 3.08.032024-12-05
CVE-2024-6516 [MEDIUM] CWE-79 CVE-2024-6516: Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be i Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2023-0636P3CRITICALCVSS 9.8≥ 3.0.0, < 3.07.012023-06-05
CVE-2023-0636 [CRITICAL] CWE-77 CVE-2023-0636: Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107
nvd
CVE-2024-51554P3CRITICALCVSS 9.8fixed in 3.08.032024-12-05
CVE-2024-51554 [CRITICAL] CWE-193 CVE-2024-51554: Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly av Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-6784P3CRITICALCVSS 9.9fixed in 3.08.032024-12-05
CVE-2024-6784 [CRITICAL] CWE-918 CVE-2024-6784: Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthori Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-51547P3CRITICALCVSS 9.8≤ 3.08.032025-02-06
CVE-2024-51547 [CRITICAL] CWE-798 CVE-2024-51547: Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX S Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
nvd
CVE-2023-0635P3CRITICALCVSS 9.8≥ 3.0.0, < 3.07.012023-06-05
CVE-2023-0635 [CRITICAL] CWE-1391 CVE-2023-0635: Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Li Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQ
nvd
CVE-2024-51549P3CRITICALCVSS 9.4fixed in 3.08.032024-12-05
CVE-2024-51549 [CRITICAL] CWE-36 CVE-2024-51549: Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. A Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
Abb Aspect-Ent-256 Firmware vulnerabilities | cvebase