CVE-2024-48840 is a critical unauthorized access vulnerability affecting ABB ASPECT - Enterprise, NEXUS Series, and MATRIX Series products (all v3.08.02). This flaw allows for unauthenticated remote code execution, posing a severe risk to the confidentiality, integrity, and availability of affected systems. With a CVSS score of 9.8, exploitation is trivial over the network and requires no user interaction. While not yet observed in active exploitation, public exploit code (EDB-52251) exists, and its high FAUCET Risk Score of 95/100 indicates a significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-2_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-256_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:aspect-ent-96_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:nexus-2128_firmware:*:*:*:*:*:*:*:* | ||
< 3.08.03CPE matchmatch criteria | cpe:2.3:o:abb:nexus-2128-a_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.