Abb Nexus-264-A Firmware vulnerabilities
28 known vulnerabilities affecting abb/nexus-264-a_firmware.
Total CVEs
28
CISA KEV
0
Public exploits
11
Exploited in wild
1
Severity breakdown
CRITICAL15HIGH11MEDIUM2
Vulnerabilities
Page 2 of 2
CVE-2024-48847P3CRITICALCVSS 9.1fixed in 3.08.032024-12-05
CVE-2024-48847 [CRITICAL] CWE-328 CVE-2024-48847: MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application depe
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.
Affected products:
ABB ASPECT - Enterprise v3.08.01;
NEXUS Series v3.08.01;
MATRIX Series v3.08.01
nvd
CVE-2024-51548P3HIGHCVSS 8.8fixed in 3.08.032024-12-05
CVE-2024-51548 [HIGH] CWE-434 CVE-2024-51548: Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products: ABB A
Dangerous File Upload vulnerabilities allow upload of malicious scripts.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-6515P3HIGHCVSS 8.1fixed in 3.08.032024-12-05
CVE-2024-6515 [HIGH] CWE-319 CVE-2024-6515: Web browser interface may manipulate application username/password in clear text or Base64 encoding
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51542P3HIGHCVSS 8.2fixed in 3.08.032024-12-05
CVE-2024-51542 [HIGH] CWE-552 CVE-2024-51542: Configuration Download vulnerabilities allow access to dependency configuration information. Affect
Configuration Download vulnerabilities allow access to dependency configuration information.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-11316P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-11316 [HIGH] CWE-770 CVE-2024-11316: Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the produ
Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51543P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-51543 [HIGH] CWE-15 CVE-2024-51543: Information Disclosure vulnerabilities allow access to application configuration information. Affec
Information Disclosure vulnerabilities allow access to application configuration information.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51541P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-51541 [HIGH] CWE-98 CVE-2024-51541: Local File Inclusion vulnerabilities allow access to sensitive system information. Affected product
Local File Inclusion vulnerabilities allow access to sensitive system information.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-48843P3HIGHCVSS 7.5fixed in 3.08.032024-12-05
CVE-2024-48843 [HIGH] CWE-770 CVE-2024-48843: Denial of Service vulnerabilities where found providing a potiential for device service disruptions.
Denial of Service vulnerabilities where found providing a potiential for device service disruptions.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
← Previous2 / 2