Linux Data Validation/Data Sanitization Vulnerabilities Affect ABB ASPECT Devices
CVE-2024-51550
9.8CRITICAL
What is CVE-2024-51550?
A vulnerability exists in ABB’s ASPECT, NEXUS, and MATRIX series products due to improper data validation and sanitization. This flaw permits the injection of unvalidated and unsanitized data into Aspect devices, potentially leading to unforeseen behavior or exposure to further attacks. Users of affected versions are advised to assess their systems for potential risks and apply available patches or mitigations from the vendor.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.08.02
MATRIX Series Linux 0 <= 3.08.02
NEXUS Series Linux 0 <= 3.08.02
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure