PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-51541 ABB CVE debrief

Local File Inclusion (LFI) vulnerabilities in ABB ASPECT allow unauthenticated remote attackers to access sensitive system information. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise, NEXUS Series, and MATRIX Series. CISA published initial advisory ICSA-25-007-01 on July 3, 2024, with subsequent updates tracking patch availability through December 5, 2024. ABB released version 3.08.03 to remediate this vulnerability. The CVSS 3.1 score of 8.2 reflects high confidentiality impact with low integrity impact, exploitable over the network without authentication. No known exploitation in ransomware campaigns has been reported.

Vendor
ABB
Product
ASPECT®-Enterprise
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2024-07-03
Original CVE updated
2024-12-05
Advisory published
2024-07-03
Advisory updated
2024-12-05

Who should care

Organizations operating ABB ASPECT building automation and energy management systems, particularly in critical infrastructure environments. Security teams responsible for OT/ICS asset protection, facility management organizations using ASPECT for building control, and compliance officers managing industrial cybersecurity frameworks should prioritize assessment and patching.

Technical summary

The vulnerability stems from improper input validation in ASPECT's file handling mechanisms, allowing path traversal sequences to access files outside intended directories. Attackers can exploit this remotely without authentication to read sensitive system files. The attack vector is network-based with low attack complexity. Affected code paths appear in web-accessible components of the ASPECT platform. Remediation requires updating to ASPECT version 3.08.03, which implements proper path validation and access controls.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade affected ABB ASPECT products to version 3.08.03 or later
  • Apply network segmentation to limit ASPECT system exposure
  • Monitor for unauthorized file access attempts in ASPECT application logs
  • Review and restrict file system permissions on ASPECT deployments
  • Implement defense-in-depth controls per CISA ICS recommended practices

Evidence notes

Source: CISA CSAF advisory ICSA-25-007-01. Affected products confirmed: ASP-ENT-x ≤3.08.02, NEX-2x ≤3.08.02, NEXUS-3-x ≤3.08.02, MAT-x ≤3.08.02. Vendor fix available in version 3.08.03 and later.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-51541 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-51541

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-51541 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-51541

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-007-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-007-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.