Abb Nexus Series vulnerabilities
58 known vulnerabilities affecting abb/nexus_series.
Total CVEs
58
CISA KEV
0
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH22MEDIUM18
Vulnerabilities
Page 1 of 3
CVE-2024-6298P1CRITICALCVSS 9.8ExploitedPoC≤ 3.08.012024-07-05
CVE-2024-6298 [CRITICAL] CWE-1287 CVE-2024-6298: Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to execute arbitrary code remotely
nvd
CVE-2024-48839P2CRITICALCVSS 9.8PoC≤ 3.08.022024-12-05
CVE-2024-48839 [CRITICAL] CWE-94 CVE-2024-48839: Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPE
Improper Input Validation vulnerability allows Remote Code Execution.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-48840P2CRITICALCVSS 9.8PoC≤ 3.08.022024-12-05
CVE-2024-48840 [CRITICAL] CWE-94 CVE-2024-48840: Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT -
Unauthorized Access vulnerabilities allow Remote Code Execution.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-6209P2HIGHCVSS 7.5PoC≤ 3.08.012024-07-05
CVE-2024-6209 [HIGH] CWE-552 CVE-2024-6209: Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to access files unauthorized
nvd
CVE-2024-48845P2CRITICALCVSS 9.8PoC≤ 3.07.022024-12-05
CVE-2024-48845 [CRITICAL] CWE-521 CVE-2024-48845: Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of wea
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.
Affected products:
ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02
nvd
CVE-2024-11317P2CRITICALCVSS 10.0PoC≤ 3.08.022024-12-05
CVE-2024-11317 [CRITICAL] CWE-384 CVE-2024-11317: Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login pr
Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51550P2CRITICALCVSS 9.8PoC≤ 3.08.022024-12-05
CVE-2024-51550 [CRITICAL] CWE-1287 CVE-2024-51550: Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized dat
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51546P3HIGHCVSS 7.5PoC≤ 3.08.022024-12-05
CVE-2024-51546 [HIGH] CWE-1287 CVE-2024-51546: Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected p
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-48846P3HIGHCVSS 7.3PoC≤ 3.08.022024-12-05
CVE-2024-48846 [HIGH] CWE-352 CVE-2024-48846: Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51555P2CRITICALCVSS 10.0≤ 3.07.022024-12-05
CVE-2024-51555 [CRITICAL] CWE-1393 CVE-2024-51555: Default Credentail vulnerabilities allows access to an Aspect device using publicly available defaul
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.
Affected products:
ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02
nvd
CVE-2024-51551P2CRITICALCVSS 10.0≤ 3.07.022024-12-05
CVE-2024-51551 [CRITICAL] CWE-1287 CVE-2024-51551: Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly av
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.
Affected products:
ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02
nvd
CVE-2024-51544P3HIGHCVSS 8.2≤ 3.08.022024-12-05
CVE-2024-51544 [HIGH] CWE-15 CVE-2024-51544: Service Control vulnerabilities allow access to service restart requests and vm configuration settin
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-48844P3MEDIUMCVSS 6.5PoC≥ initial, ≤ 3.08.022024-12-05
CVE-2024-48844 [MEDIUM] CWE-770 CVE-2024-48844: Denial of Service vulnerabilities where found providing a potiential for device service disruptions.
Denial of Service vulnerabilities where found providing a potiential for device service disruptions.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-6516P3MEDIUMCVSS 6.1PoC≤ 3.08.012024-12-05
CVE-2024-6516 [MEDIUM] CWE-79 CVE-2024-6516: Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be i
Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-13955P3HIGHCVSS 8.8≤ 3.*2025-05-22
CVE-2024-13955 [HIGH] CWE-89 CVE-2024-13955: 2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of databa
2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
nvd
CVE-2024-51554P3CRITICALCVSS 9.8≤ 3.08.022024-12-05
CVE-2024-51554 [CRITICAL] CWE-193 CVE-2024-51554: Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly av
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-48853P3CRITICALCVSS 9.0≤ 3.08.032025-05-22
CVE-2024-48853 [CRITICAL] CWE-286 CVE-2024-48853: An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server
An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-6784P3CRITICALCVSS 9.9≤ 3.08.022024-12-05
CVE-2024-6784 [CRITICAL] CWE-918 CVE-2024-6784: Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthori
Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51547P3CRITICALCVSS 9.8≤ 3.*2025-02-06
CVE-2024-51547 [CRITICAL] CWE-798 CVE-2024-51547: Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX S
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
nvd
CVE-2024-13946P3MEDIUMCVSS 6.8PoC≤ 3.*2025-05-22
CVE-2024-13946 [MEDIUM] CWE-427 CVE-2024-13946: DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the applicatio
DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
nvd
1 / 3Next →