← back
CVE-2024-48840criticalCWE-94

Unauthorized Access

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.3epss 2.1%
from disclosure to weapon133 days
Published on NVDDec 5
1st PoC+133d
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

A critical flaw in ABB ASPECT Enterprise, NEXUS Series, and MATRIX Series allows attackers to execute malicious code remotely without proper authorization. This means an attacker could take complete control of affected systems.

Technical detail

CWE-94 (Code Injection) vulnerability enabling unauthenticated remote code execution in ABB products (ASPECT Enterprise v3.08.02, NEXUS Series v3.08.02, MATRIX Series v3.08.02). The vulnerability permits attackers to inject and execute arbitrary code within the application context, potentially compromising system integrity and confidentiality. Immediate patching is required to mitigate critical risk.

Summary generated and translated by AI from the official description.
Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.