Large Content Vulnerabilities in ASPECT Affecting ABB Devices
CVE-2024-13949

6.9MEDIUM

Key Information:

Vendor

Abb

Vendor
CVE Published:
22 May 2025

What is CVE-2024-13949?

An alarming vulnerability has been identified in ABB's ASPECT, which could lead to disk overutilization if administrator credentials are compromised. This issue affects the ASPECT-Enterprise product, as well as the NEXUS and MATRIX Series, all vulnerable through version 3.*. Administrators should take immediate action to mitigate the risks associated with this vulnerability to protect their systems from potential exploitation.

Affected Version(s)

ASPECT-Enterprise Linux 0 <= 3.*

MATRIX Series Linux 0 <= 3.*

NEXUS Series Linux 0 <= 3.*

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
.