Large Content Vulnerabilities in ASPECT and NEXUS Series by ABB
CVE-2024-48848
7HIGH
What is CVE-2024-48848?
ABB devices are exposed to significant risks due to large content vulnerabilities found in the ASPECT, NEXUS Series, and MATRIX Series products. These vulnerabilities can lead to disk overutilization if an attacker manages to compromise administrator credentials. Affected versions include ASPECT-Enterprise through 3., NEXUS Series through 3., and MATRIX Series through 3.*. Organizations using these products should take immediate steps to mitigate potential threats.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.*
MATRIX Series Linux 0 <= 3.*
NEXUS Series Linux 0 <= 3.*
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure