PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-48841 ABB CVE debrief

CVE-2024-48841 is a critical ABB FLXEON controller vulnerability that allows network-based execution of arbitrary code with elevated privileges. The advisory affects FLXEON products at firmware 9.3.4 and earlier, with CISA listing FBXi, FBVi, FBTi, and CBXi firmware as impacted. ABB and CISA recommend immediate exposure reduction and firmware upgrade to 9.3.5 or later.

Vendor
ABB
Product
FLXEON Controllers
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2025-01-23
Original CVE updated
2025-02-14
Advisory published
2025-01-23
Advisory updated
2025-02-14

Who should care

OT/ICS operators, plant engineers, security teams, and integrators responsible for ABB FLXEON deployments—especially systems exposed to the internet, reachable through NAT port forwarding, or used for remote access.

Technical summary

The supplied advisory describes a network-accessible arbitrary code execution flaw with elevated privileges. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates remote exploitation without authentication or user interaction, with potential impact across confidentiality, integrity, and availability. CISA’s CSAF advisory ties the issue to ABB FLXEON family products and explicitly lists FBXi, FBVi, FBTi, and CBXi firmware versions <= 9.3.4 as affected.

Defensive priority

Immediate

Recommended defensive actions

  • Upgrade all affected FLXEON products to firmware 9.3.5 or above.
  • Stop and disconnect any FLXEON products exposed directly to the internet, including via direct ISP connections or NAT port forwarding.
  • Restrict remote access to secure methods only; if VPN is used, ensure it is fully updated and configured for secure access.
  • Verify physical access controls so unauthorized personnel cannot access devices, components, peripheral equipment, or networks.
  • Inventory ABB FLXEON deployments and confirm whether FBXi, FBVi, FBTi, or CBXi firmware versions are at or below 9.3.4.

Evidence notes

Primary evidence comes from CISA’s CSAF advisory ICSA-25-051-02 for ABB FLXEON Controllers, published 2025-01-23 and revised 2025-02-14. The advisory text states: 'Network access can be used to execute arbitrary code with elevated privileges' and identifies affected firmware as <= 9.3.4. The remediation section directs users to upgrade to 9.3.5 or above and to remove direct internet exposure. The revision history notes a later correction in the CWE entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-48841 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-48841

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-48841 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-48841

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-051-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-051-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.