These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A critical vulnerability in ABB ASPECT building automation systems allows credential exposure through the web browser interface. The application handles usernames and passwords in clear text or Base64 encoding, significantly increasing the risk of unintended credential disclosure. This affects ASPECT-Enterprise, NEXUS Series, and MATRIX Series products running version 3.08.02 and earlier. The vulnerabilit [truncated]
A critical Improper Input Validation vulnerability in ABB ASPECT systems enables Remote Code Inclusion (RCI) with a CVSS 3.1 score of 10.0. The flaw affects ASPECT-Enterprise, NEXUS Series, and MATRIX Series products running version 3.08.01 and earlier. CISA published advisory ICSA-25-007-01 on July 3, 2024, with subsequent updates in August, November, and December 2024 as patched versions became availabl [truncated]
CVE-2024-51554 is a critical off-by-one error vulnerability in ABB's ASPECT building automation system that enables array out-of-bounds access in a log script. Published July 3, 2024, and last modified December 5, 2024, this vulnerability carries a CVSS 3.1 score of 9.1 (Critical). The flaw affects multiple ABB product lines including ASPECT®-Enterprise (ASP-ENT-x), NEXUS Series (NEX-2x, NEXUS-3-x), and M [truncated]
ABB ASPECT systems ship with publicly known default credentials that allow unauthenticated remote attackers to gain full administrative access to affected devices. The vulnerability affects ASPECT-Enterprise, NEXUS Series, and MATRIX Series products running version 3.07.02 and earlier on Linux. CISA published this advisory on July 3, 2024, with subsequent updates in August, November, and December 2024 as [truncated]
A critical file upload vulnerability in ABB ASPECT building automation systems allows authenticated attackers to upload and execute malicious scripts. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT-Enterprise, NEXUS Series, and MATRIX Series. ABB has released version 3.08.03 to address this issue. The vulnerability was disclosed on July 3, 2024 [truncated]
ABB ASPECT systems contain a credentials disclosure vulnerability that allows unauthorized access to on-board project backup bundles. The vulnerability affects ASPECT firmware versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise (ASP-ENT-x), NEXUS Series (NEX-2x, NEXUS-3-x), and MATRIX Series (MAT-x) devices. CISA published this advisory on July 3, 2024, with subsequent [truncated]
Service Control vulnerabilities in ABB ASPECT allow unauthorized access to service restart requests and VM configuration settings. Affected versions are 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise, NEXUS Series, and MATRIX Series. The vulnerability has a CVSS 3.1 score of 8.2 (HIGH severity). Vendor fixes are available in version 3.08.03 and later.
CVE-2024-51543 is a HIGH severity information disclosure vulnerability affecting ABB ASPECT building automation systems. The vulnerability allows unauthenticated remote attackers to access sensitive application configuration information. The affected products include ASPECT®-Enterprise (ASP-ENT-x), NEXUS Series (NEX-2x, NEXUS-3-x), and MATRIX Series (MAT-x) running firmware version 3.08.02 and earlier. Th [truncated]
CVE-2024-51542 is a HIGH severity configuration download vulnerability in ABB ASPECT building automation systems, published 2024-07-03. The flaw allows unauthorized access to dependency configuration information in affected products running firmware version 3.08.02 and earlier. ABB has released version 3.08.03 to remediate this issue. The vulnerability affects multiple product lines including ASPECT-Enter [truncated]
Local File Inclusion (LFI) vulnerabilities in ABB ASPECT allow unauthenticated remote attackers to access sensitive system information. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise, NEXUS Series, and MATRIX Series. CISA published initial advisory ICSA-25-007-01 on July 3, 2024, with subsequent updates tracking patch availability t [truncated]
Cross-Site Request Forgery (CSRF) vulnerabilities in ABB ASPECT building automation systems enable attackers to perform unauthorized actions on behalf of authenticated users. The vulnerability affects multiple product lines including ASPECT-Enterprise, NEXUS Series, and MATRIX Series running firmware version 3.08.02 and earlier. Successful exploitation could result in exposure of sensitive information or [truncated]
ABB ASPECT systems are affected by Denial of Service vulnerabilities that could lead to device service disruptions. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise (ASP-ENT-x), NEXUS Series (NEX-2x, NEXUS-3-x), and MATRIX Series (MAT-x). ABB has released version 3.08.03 to address these issues. The vulnerability was initially disclos [truncated]
SQL injection vulnerabilities in ABB ASPECT building automation systems enable unintended information disclosure. Affected versions span ASPECT-Enterprise (ASP-ENT-x), NEXUS Series (NEX-2x, NEXUS-3-x), and MATRIX Series (MAT-x) all at version 3.08.02 and earlier. CISA published advisory ICSA-25-007-01 on 2024-07-03 with subsequent revisions tracking patch availability through December 2024. Vendor fix ver [truncated]
A critical improper input validation vulnerability in ABB ASPECT building automation systems enables unauthenticated remote code execution. Affected versions ≤3.08.02 across ASPECT-Enterprise, NEXUS Series, and MATRIX Series product lines are vulnerable. CISA published advisory ICSA-25-007-01 on 2024-07-03, with subsequent updates through December 2024 tracking patch availability. ABB released version 3.0 [truncated]
Session fixation vulnerabilities in ABB ASPECT systems allow attackers to predetermine a user's session identifier prior to authentication, enabling session takeover on affected devices. The vulnerability affects ASPECT versions 3.08.02 and earlier across multiple product lines including ASPECT®-Enterprise (ASP-ENT-x), NEXUS Series (NEX-2x, NEXUS-3-x), and MATRIX Series (MAT-x) devices. This is rated CRIT [truncated]
A file size validation vulnerability in ABB ASPECT building automation systems allows network-based attackers to bypass size limits or cause device overload, resulting in denial of service. The flaw affects ASPECT firmware versions 3.08.02 and earlier across multiple product lines including ASPECT-Enterprise, NEXUS Series, and MATRIX Series controllers. CISA published advisory ICSA-25-007-01 on July 3, 20 [truncated]
CVE-2024-3036 is a medium-severity vulnerability in ABB 800xA Base, an industrial control system platform used in process automation environments. Published on June 5, 2024, and last modified on May 19, 2026, this vulnerability allows an attacker with adjacent network access and low privileges to cause denial of service conditions by sending specially crafted messages that crash system services. The vulne [truncated]