cbcvebase.

Abb Aspect-Ent-2 Firmware vulnerabilities

29 known vulnerabilities affecting abb/aspect-ent-2_firmware.

Total CVEs
29
CISA KEV
0
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH12MEDIUM2

Vulnerabilities

Page 2 of 2
CVE-2024-51545P3CRITICALCVSS 9.8fixed in 3.08.032024-12-05
CVE-2024-51545 [CRITICAL] CWE-522 CVE-2024-51545: Username Enumeration vulnerabilities allow access to application level username add, delete, modify Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-48847P3CRITICALCVSS 9.1fixed in 3.08.032024-12-05
CVE-2024-48847 [CRITICAL] CWE-328 CVE-2024-48847: MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application depe MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes. Affected products: ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRIX Series v3.08.01
nvd
CVE-2024-51548P3HIGHCVSS 8.8fixed in 3.08.032024-12-05
CVE-2024-51548 [HIGH] CWE-434 CVE-2024-51548: Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products: ABB A Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-6515P3HIGHCVSS 8.1fixed in 3.08.032024-12-05
CVE-2024-6515 [HIGH] CWE-319 CVE-2024-6515: Web browser interface may manipulate application username/password in clear text or Base64 encoding Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-51542P3HIGHCVSS 8.2fixed in 3.08.032024-12-05
CVE-2024-51542 [HIGH] CWE-552 CVE-2024-51542: Configuration Download vulnerabilities allow access to dependency configuration information. Affect Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-11316P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-11316 [HIGH] CWE-770 CVE-2024-11316: Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the produ Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-51543P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-51543 [HIGH] CWE-15 CVE-2024-51543: Information Disclosure vulnerabilities allow access to application configuration information. Affec Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-51541P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-51541 [HIGH] CWE-98 CVE-2024-51541: Local File Inclusion vulnerabilities allow access to sensitive system information. Affected product Local File Inclusion vulnerabilities allow access to sensitive system information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
CVE-2024-48843P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-48843 [HIGH] CWE-770 CVE-2024-48843: Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
nvd
Abb Aspect-Ent-2 Firmware vulnerabilities | cvebase