PatchSiren cyber security CVE debrief
CVE-2024-48852 ABB CVE debrief
CISA’s advisory for ABB FLXEON Controllers says some information may be improperly disclosed through HTTPS access in firmware 9.3.4 and earlier. The vendor’s remediation is to upgrade to 9.3.5 or later, avoid direct Internet exposure, and use secure remote-access controls such as a properly maintained VPN.
- Vendor
- ABB
- Product
- FLXEON Controllers
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-23
- Original CVE updated
- 2025-02-14
- Advisory published
- 2025-01-23
- Advisory updated
- 2025-02-14
Who should care
Operators of ABB FLXEON Controllers and related FBXi, FBVi, FBTi, and CBXi firmware at version 9.3.4 or below, especially environments exposing device management or HTTPS services beyond an internal network.
Technical summary
The advisory describes a network-reachable information disclosure condition affecting ABB FLXEON-family firmware versions <= 9.3.4. The supplied CVSS vector indicates no privileges or user interaction are required, with network attack complexity low. CISA’s product tree names affected FBXi, FBVi, FBTi, and CBXi firmware under ABB’s FLXEON Controllers umbrella, and recommends upgrading to firmware 9.3.5 or above.
Defensive priority
High. The CVSS score is 9.4 (Critical), the issue is network-accessible, and the remediation is straightforward: upgrade firmware and reduce exposure. Even though the supplied enrichment does not list the CVE in CISA KEV, internet-facing or remotely reachable controllers should be addressed promptly.
Recommended defensive actions
- Upgrade ABB FLXEON-family firmware to 9.3.5 or later on all affected devices.
- Disconnect FLXEON products from direct Internet exposure, including ISP connections and NAT port forwarding.
- Restrict management and HTTPS access to trusted internal networks only.
- Use a secure, fully patched VPN for any required remote access.
- Confirm physical access controls prevent unauthorized access to devices, peripherals, and network equipment.
- Inventory FBXi, FBVi, FBTi, and CBXi devices to verify whether any remain at version 9.3.4 or below.
Evidence notes
The vulnerability description and affected-version scope come from the CISA CSAF advisory for ICSA-25-051-02, which lists ABB as vendor and FLXEON-family firmware versions <= 9.3.4. ABB remediation text explicitly recommends upgrading to 9.3.5 or above and avoiding direct Internet exposure. The published and modified dates are taken from the supplied CVE/timeline fields, not from this response date.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-48852 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-48852
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-48852 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-48852
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-051-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-051-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.