PatchSiren cyber security CVE debrief
CVE-2024-51541 ABB CVE debrief
Local File Inclusion (LFI) vulnerabilities in ABB ASPECT allow unauthenticated remote attackers to access sensitive system information. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise, NEXUS Series, and MATRIX Series. CISA published initial advisory ICSA-25-007-01 on July 3, 2024, with subsequent updates tracking patch availability through December 5, 2024. ABB released version 3.08.03 to remediate this vulnerability. The CVSS 3.1 score of 8.2 reflects high confidentiality impact with low integrity impact, exploitable over the network without authentication. No known exploitation in ransomware campaigns has been reported.
- Vendor
- ABB
- Product
- ASPECT®-Enterprise
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-03
- Original CVE updated
- 2024-12-05
- Advisory published
- 2024-07-03
- Advisory updated
- 2024-12-05
Who should care
Organizations operating ABB ASPECT building automation and energy management systems, particularly in critical infrastructure environments. Security teams responsible for OT/ICS asset protection, facility management organizations using ASPECT for building control, and compliance officers managing industrial cybersecurity frameworks should prioritize assessment and patching.
Technical summary
The vulnerability stems from improper input validation in ASPECT's file handling mechanisms, allowing path traversal sequences to access files outside intended directories. Attackers can exploit this remotely without authentication to read sensitive system files. The attack vector is network-based with low attack complexity. Affected code paths appear in web-accessible components of the ASPECT platform. Remediation requires updating to ASPECT version 3.08.03, which implements proper path validation and access controls.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade affected ABB ASPECT products to version 3.08.03 or later
- Apply network segmentation to limit ASPECT system exposure
- Monitor for unauthorized file access attempts in ASPECT application logs
- Review and restrict file system permissions on ASPECT deployments
- Implement defense-in-depth controls per CISA ICS recommended practices
Evidence notes
Source: CISA CSAF advisory ICSA-25-007-01. Affected products confirmed: ASP-ENT-x ≤3.08.02, NEX-2x ≤3.08.02, NEXUS-3-x ≤3.08.02, MAT-x ≤3.08.02. Vendor fix available in version 3.08.03 and later.
Official resources
-
CVE-2024-51541 CVE record
CVE.org
-
CVE-2024-51541 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
CISA published advisory ICSA-25-007-01 on July 3, 2024, with revisions on August 20, 2024 (ASPECT 3.08.02 availability), November 28, 2024 (ASPECT 3.08.03 availability), and December 5, 2024 (acknowledgment correction).