PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-51541 ABB CVE debrief

Local File Inclusion (LFI) vulnerabilities in ABB ASPECT allow unauthenticated remote attackers to access sensitive system information. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise, NEXUS Series, and MATRIX Series. CISA published initial advisory ICSA-25-007-01 on July 3, 2024, with subsequent updates tracking patch availability through December 5, 2024. ABB released version 3.08.03 to remediate this vulnerability. The CVSS 3.1 score of 8.2 reflects high confidentiality impact with low integrity impact, exploitable over the network without authentication. No known exploitation in ransomware campaigns has been reported.

Vendor
ABB
Product
ASPECT®-Enterprise
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2024-07-03
Original CVE updated
2024-12-05
Advisory published
2024-07-03
Advisory updated
2024-12-05

Who should care

Organizations operating ABB ASPECT building automation and energy management systems, particularly in critical infrastructure environments. Security teams responsible for OT/ICS asset protection, facility management organizations using ASPECT for building control, and compliance officers managing industrial cybersecurity frameworks should prioritize assessment and patching.

Technical summary

The vulnerability stems from improper input validation in ASPECT's file handling mechanisms, allowing path traversal sequences to access files outside intended directories. Attackers can exploit this remotely without authentication to read sensitive system files. The attack vector is network-based with low attack complexity. Affected code paths appear in web-accessible components of the ASPECT platform. Remediation requires updating to ASPECT version 3.08.03, which implements proper path validation and access controls.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade affected ABB ASPECT products to version 3.08.03 or later
  • Apply network segmentation to limit ASPECT system exposure
  • Monitor for unauthorized file access attempts in ASPECT application logs
  • Review and restrict file system permissions on ASPECT deployments
  • Implement defense-in-depth controls per CISA ICS recommended practices

Evidence notes

Source: CISA CSAF advisory ICSA-25-007-01. Affected products confirmed: ASP-ENT-x ≤3.08.02, NEX-2x ≤3.08.02, NEXUS-3-x ≤3.08.02, MAT-x ≤3.08.02. Vendor fix available in version 3.08.03 and later.

Official resources

CISA published advisory ICSA-25-007-01 on July 3, 2024, with revisions on August 20, 2024 (ASPECT 3.08.02 availability), November 28, 2024 (ASPECT 3.08.03 availability), and December 5, 2024 (acknowledgment correction).