PatchSiren cyber security CVE debrief
CVE-2024-51541 ABB CVE debrief
Local File Inclusion (LFI) vulnerabilities in ABB ASPECT allow unauthenticated remote attackers to access sensitive system information. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise, NEXUS Series, and MATRIX Series. CISA published initial advisory ICSA-25-007-01 on July 3, 2024, with subsequent updates tracking patch availability through December 5, 2024. ABB released version 3.08.03 to remediate this vulnerability. The CVSS 3.1 score of 8.2 reflects high confidentiality impact with low integrity impact, exploitable over the network without authentication. No known exploitation in ransomware campaigns has been reported.
- Vendor
- ABB
- Product
- ASPECT®-Enterprise
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-03
- Original CVE updated
- 2024-12-05
- Advisory published
- 2024-07-03
- Advisory updated
- 2024-12-05
Who should care
Organizations operating ABB ASPECT building automation and energy management systems, particularly in critical infrastructure environments. Security teams responsible for OT/ICS asset protection, facility management organizations using ASPECT for building control, and compliance officers managing industrial cybersecurity frameworks should prioritize assessment and patching.
Technical summary
The vulnerability stems from improper input validation in ASPECT's file handling mechanisms, allowing path traversal sequences to access files outside intended directories. Attackers can exploit this remotely without authentication to read sensitive system files. The attack vector is network-based with low attack complexity. Affected code paths appear in web-accessible components of the ASPECT platform. Remediation requires updating to ASPECT version 3.08.03, which implements proper path validation and access controls.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade affected ABB ASPECT products to version 3.08.03 or later
- Apply network segmentation to limit ASPECT system exposure
- Monitor for unauthorized file access attempts in ASPECT application logs
- Review and restrict file system permissions on ASPECT deployments
- Implement defense-in-depth controls per CISA ICS recommended practices
Evidence notes
Source: CISA CSAF advisory ICSA-25-007-01. Affected products confirmed: ASP-ENT-x ≤3.08.02, NEX-2x ≤3.08.02, NEXUS-3-x ≤3.08.02, MAT-x ≤3.08.02. Vendor fix available in version 3.08.03 and later.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-51541 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-51541
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-51541 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-51541
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-007-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-007-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.