CVE-2024-48847
8.8
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: cybersecurity@ch.abb.com (Secondary)
Description
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.
Affected products:
ABB ASPECT - Enterprise v3.08.01;
NEXUS Series v3.08.01;
MATRIX Series v3.08.01
Affected (19)
Products: Abb: Aspect Ent 2 Firmware, Aspect Ent 256 Firmware, Aspect Ent 96 Firmware, Nexus 2128 Firmware, Nexus 2128 A Firmware, Nexus 2128 F Firmware, Nexus 2128 G Firmware, Nexus 264 Firmware, Nexus 264 A Firmware, Nexus 264 G Firmware, Nexus 3 2128 Firmware, Aspect Ent 12 Firmware, Nexus 264 F Firmware, Nexus 3 264 Firmware, Matrix 11 Firmware, Matrix 216 Firmware, Matrix 232 Firmware, Matrix 264 Firmware, Matrix 296 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 256 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 96 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 A | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 F | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 G | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 A | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 G | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 3 2128 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.08.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 12 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.08.03 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 F | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.08.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 3 264 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.08.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 11 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.08.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 216 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.08.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 232 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.08.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 264 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.08.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 296 | All versions |
Related CWEs
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CWE-328
Use of Weak Hash
The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
References (1)
Source: cybersecurity@ch.abb.com
Vendor Advisory
Timeline
No history available yet.