CVE-2024-48843
7.6
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:X/U:RedShow more
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:X/U:RedShow less
Source: cybersecurity@ch.abb.com (Secondary)
Description
Denial of Service vulnerabilities where found providing a potiential for device service disruptions.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
Affected (19)
Products: Abb: Aspect Ent 2 Firmware, Aspect Ent 256 Firmware, Aspect Ent 96 Firmware, Nexus 2128 Firmware, Nexus 2128 A Firmware, Nexus 2128 F Firmware, Nexus 2128 G Firmware, Nexus 264 Firmware, Nexus 264 A Firmware, Nexus 264 G Firmware, Nexus 3 2128 Firmware, Aspect Ent 12 Firmware, Nexus 264 F Firmware, Nexus 3 264 Firmware, Matrix 11 Firmware, Matrix 216 Firmware, Matrix 232 Firmware, Matrix 264 Firmware, Matrix 296 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 256 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 96 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 A | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 F | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 G | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 A | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 G | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 3 2128 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 12 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 F | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 3 264 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 11 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 216 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 232 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 264 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 296 | All versions |
Related CWEs
CWE-770
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
References (1)
Source: cybersecurity@ch.abb.com
Vendor Advisory
Timeline
No history available yet.