CVE-2024-48840: critical vulnerability in ABB NEXUS Series
Unauthorized Access
Published
No sign of exploitation. It has a public proof of concept.
A critical flaw in ABB ASPECT Enterprise, NEXUS Series, and MATRIX Series allows attackers to execute malicious code remotely without proper authorization. This means an attacker could take complete control of affected systems.
CWE-94 (Code Injection) vulnerability enabling unauthenticated remote code execution in ABB products (ASPECT Enterprise v3.08.02, NEXUS Series v3.08.02, MATRIX Series v3.08.02). The vulnerability permits attackers to inject and execute arbitrary code within the application context, potentially compromising system integrity and confidentiality. Immediate patching is required to mitigate critical risk.
In the same product, most dangerous first.