Abb Nexus Series vulnerabilities
58 known vulnerabilities affecting abb/nexus_series.
Total CVEs
58
CISA KEV
0
Public exploits
12
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH22MEDIUM18
Vulnerabilities
Page 2 of 3
CVE-2024-51549P3CRITICALCVSS 9.4≤ 3.08.022024-12-05
CVE-2024-51549 [CRITICAL] CWE-36 CVE-2024-51549: Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. A
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51545P3CRITICALCVSS 9.8≤ 3.08.022024-12-05
CVE-2024-51545 [CRITICAL] CWE-522 CVE-2024-51545: Username Enumeration vulnerabilities allow access to application level username add, delete, modify
Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2025-2410P3CRITICALCVSS 9.1≤ 3.08.032025-05-22
CVE-2025-2410 [CRITICAL] CWE-99 CVE-2025-2410: Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP po
Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised.
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-48847P3CRITICALCVSS 9.1≤ 3.08.012024-12-05
CVE-2024-48847 [CRITICAL] CWE-328 CVE-2024-48847: MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application depe
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.
Affected products:
ABB ASPECT - Enterprise v3.08.01;
NEXUS Series v3.08.01;
MATRIX Series v3.08.01
nvd
CVE-2024-51548P3HIGHCVSS 8.8≤ 3.08.022024-12-05
CVE-2024-51548 [HIGH] CWE-434 CVE-2024-51548: Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products: ABB A
Dangerous File Upload vulnerabilities allow upload of malicious scripts.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2025-2409P3CRITICALCVSS 9.1≤ 3.08.032025-05-22
CVE-2025-2409 [CRITICAL] CWE-73 CVE-2025-2409: File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if ses
File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2025-30171P3CRITICALCVSS 9.0≤ 3.08.032025-05-22
CVE-2025-30171 [CRITICAL] CWE-863 CVE-2025-30171: System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if se
System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised.
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-13929P3HIGHCVSS 7.2≤ 3.08.032025-05-22
CVE-2024-13929 [HIGH] CWE-94 CVE-2024-13929: Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator cre
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised.
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-9639P3HIGHCVSS 8.0≤ 3.08.032025-05-22
CVE-2024-9639 [HIGH] CWE-94 CVE-2024-9639: Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials be
Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised.
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-6515P3HIGHCVSS 8.1≤ 3.08.022024-12-05
CVE-2024-6515 [HIGH] CWE-319 CVE-2024-6515: Web browser interface may manipulate application username/password in clear text or Base64 encoding
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2025-30172P3HIGHCVSS 8.0≤ 3.08.032025-05-22
CVE-2025-30172 [HIGH] CWE-94 CVE-2025-30172: Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials bec
Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-13928P3HIGHCVSS 7.2≤ 3.08.032025-05-22
CVE-2024-13928 [HIGH] CWE-94 CVE-2024-13928: SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database reposit
SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised.
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-51542P3HIGHCVSS 8.2≤ 3.08.022024-12-05
CVE-2024-51542 [HIGH] CWE-552 CVE-2024-51542: Configuration Download vulnerabilities allow access to dependency configuration information. Affect
Configuration Download vulnerabilities allow access to dependency configuration information.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-48850P3HIGHCVSS 7.2≤ 3.08.032025-05-22
CVE-2024-48850 [HIGH] CWE-36 CVE-2024-48850: Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resou
Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources.
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-13931P3HIGHCVSS 7.2≤ 3.08.032025-05-22
CVE-2024-13931 [HIGH] CWE-606 CVE-2024-13931: Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administ
Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised.
This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
nvd
CVE-2024-11316P3HIGHCVSS 7.5≤ 3.08.022024-12-05
CVE-2024-11316 [HIGH] CWE-770 CVE-2024-11316: Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the produ
Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-13951P3HIGHCVSS 7.6≤ 3.*2025-05-22
CVE-2024-13951 [HIGH] CWE-760 CVE-2024-13951: One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a p
One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
nvd
CVE-2024-51543P3HIGHCVSS 7.5≤ 3.08.022024-12-05
CVE-2024-51543 [HIGH] CWE-15 CVE-2024-51543: Information Disclosure vulnerabilities allow access to application configuration information. Affec
Information Disclosure vulnerabilities allow access to application configuration information.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-51541P3HIGHCVSS 7.5≤ 3.08.022024-12-05
CVE-2024-51541 [HIGH] CWE-98 CVE-2024-51541: Local File Inclusion vulnerabilities allow access to sensitive system information. Affected product
Local File Inclusion vulnerabilities allow access to sensitive system information.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
nvd
CVE-2024-13957P3HIGHCVSS 7.6≤ 3.*2025-05-22
CVE-2024-13957 [HIGH] CWE-918 CVE-2024-13957: SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become
SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
nvd