PatchSiren cyber security CVE debrief
CVE-2024-48841 ABB CVE debrief
CVE-2024-48841 is a critical ABB FLXEON controller vulnerability that allows network-based execution of arbitrary code with elevated privileges. The advisory affects FLXEON products at firmware 9.3.4 and earlier, with CISA listing FBXi, FBVi, FBTi, and CBXi firmware as impacted. ABB and CISA recommend immediate exposure reduction and firmware upgrade to 9.3.5 or later.
- Vendor
- ABB
- Product
- FLXEON Controllers
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-23
- Original CVE updated
- 2025-02-14
- Advisory published
- 2025-01-23
- Advisory updated
- 2025-02-14
Who should care
OT/ICS operators, plant engineers, security teams, and integrators responsible for ABB FLXEON deployments—especially systems exposed to the internet, reachable through NAT port forwarding, or used for remote access.
Technical summary
The supplied advisory describes a network-accessible arbitrary code execution flaw with elevated privileges. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates remote exploitation without authentication or user interaction, with potential impact across confidentiality, integrity, and availability. CISA’s CSAF advisory ties the issue to ABB FLXEON family products and explicitly lists FBXi, FBVi, FBTi, and CBXi firmware versions <= 9.3.4 as affected.
Defensive priority
Immediate
Recommended defensive actions
- Upgrade all affected FLXEON products to firmware 9.3.5 or above.
- Stop and disconnect any FLXEON products exposed directly to the internet, including via direct ISP connections or NAT port forwarding.
- Restrict remote access to secure methods only; if VPN is used, ensure it is fully updated and configured for secure access.
- Verify physical access controls so unauthorized personnel cannot access devices, components, peripheral equipment, or networks.
- Inventory ABB FLXEON deployments and confirm whether FBXi, FBVi, FBTi, or CBXi firmware versions are at or below 9.3.4.
Evidence notes
Primary evidence comes from CISA’s CSAF advisory ICSA-25-051-02 for ABB FLXEON Controllers, published 2025-01-23 and revised 2025-02-14. The advisory text states: 'Network access can be used to execute arbitrary code with elevated privileges' and identifies affected firmware as <= 9.3.4. The remediation section directs users to upgrade to 9.3.5 or above and to remove direct internet exposure. The revision history notes a later correction in the CWE entry.
Official resources
-
CVE-2024-48841 CVE record
CVE.org
-
CVE-2024-48841 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
CISA published the advisory on 2025-01-23 and updated it on 2025-02-14; the advisory’s published date is the correct timing reference for this CVE.