ABB
ABB Matrix-296 Firmware: vulnerabilidades y CVE
ABB Matrix-296 Firmware tiene 29 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses0
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-51547 | Crítica (9.3) | 0.62% | — | 6 feb 2025 | Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. |
| CVE-2024-6784 | Alta (8.7) | 0.50% | — | 5 dic 2024 | Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure. Affected products: |
| CVE-2024-6516 | Crítica (9.3) | 1.1% | — | 5 dic 2024 | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products: |
| CVE-2024-6515 | Alta (8.7) | 0.40% | — | 5 dic 2024 | Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure. Affected products: |
| CVE-2024-51554 | Alta (8.8) | 0.39% | — | 5 dic 2024 | Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: |
| CVE-2024-51551 | Crítica (9.3) | 0.45% | — | 5 dic 2024 | Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: |
| CVE-2024-51550 | Crítica (9.3) | 1.8% | — | 5 dic 2024 | Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected products: |
| CVE-2024-51549 | Crítica (9.3) | 0.54% | — | 5 dic 2024 | Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products: |
| CVE-2024-51548 | Alta (8.7) | 0.59% | — | 5 dic 2024 | Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products: |
| CVE-2024-51546 | Alta (8.7) | 1.5% | — | 5 dic 2024 | Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: |
| CVE-2024-51545 | Crítica (9.3) | 0.43% | — | 5 dic 2024 | Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. Affected products: |
| CVE-2024-51544 | Alta (8.8) | 13% | — | 5 dic 2024 | Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products: |
| CVE-2024-51543 | Alta (8.8) | 0.33% | — | 5 dic 2024 | Information Disclosure vulnerabilities allow access to application configuration information. Affected products: |
| CVE-2024-51542 | Alta (8.8) | 0.33% | — | 5 dic 2024 | Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: |
| CVE-2024-51541 | Alta (8.8) | 0.32% | — | 5 dic 2024 | Local File Inclusion vulnerabilities allow access to sensitive system information. Affected products: |
| CVE-2024-48847 | Alta (8.8) | 0.26% | — | 5 dic 2024 | MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes. Affected products: |
| CVE-2024-48846 | Alta (7.1) | 0.64% | — | 5 dic 2024 | Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. Affected products: |
| CVE-2024-48845 | Crítica (9.3) | 1.8% | — | 5 dic 2024 | Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: |
| CVE-2024-48844 | Alta (7.2) | 0.87% | — | 5 dic 2024 | Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: |
| CVE-2024-48843 | Alta (7.6) | 0.28% | — | 5 dic 2024 | Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: |
| CVE-2024-48840 | Crítica (9.3) | 2.1% | — | 5 dic 2024 | Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: |
| CVE-2024-48839 | Crítica (9.3) | 2.8% | — | 5 dic 2024 | Improper Input Validation vulnerability allows Remote Code Execution. Affected products: |
| CVE-2024-11317 | Crítica (9.3) | 0.43% | — | 5 dic 2024 | Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product. Affected products: |
| CVE-2024-11316 | Alta (8.7) | 0.62% | — | 5 dic 2024 | Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product. Affected products: |
| CVE-2024-6298 | Crítica (9.4) | 19% | — | 5 jul 2024 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely |
| CVE-2024-6209 | Crítica (9.4) | 17% | — | 5 jul 2024 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized |
| CVE-2024-4007 | Alta (8.7) | 1.5% | — | 1 jul 2024 | Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. |
| CVE-2023-0636 | Crítica (9.8) | 1.4% | — | 5 jun 2023 | Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series,… |
| CVE-2023-0635 | Crítica (9.8) | 0.37% | — | 5 jun 2023 | Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de ABB
Nexus-2128 Firmware · 29Nexus-3-2128 Firmware · 29Aspect-ent-2 Firmware · 29Matrix-264 Firmware · 29Nexus-264 Firmware · 29Matrix-216 Firmware · 29Aspect-ent-12 Firmware · 29Aspect-ent-256 Firmware · 29Aspect-ent-96 Firmware · 29Matrix-11 Firmware · 29Matrix-232 Firmware · 29Nexus-3-264 Firmware · 29