CVE-2024-48839
Remote Code Execution, RCE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
8Exploited in Wild
-Decision
Descriptions
Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
ABB Cylon Aspect version 3.08.02 is vulnerable to code execution and sudo misconfiguration flaws. An authenticated remote code execution vulnerability in the firmware update mechanism allows an attacker with valid credentials to escalate privileges and execute commands as root. The process involves uploading a crafted .aam file through fileSystemUpdate.php, which is then moved to /tmp and executed by fileSystemUpdateExecute.php. This script leverages sudo to run the upgrade-bundle.sh script, enabling the attacker to bypass input validation checks and execute arbitrary code, leading to full system compromise and unauthorized root access.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-10-08 CVE Reserved
- 2024-12-05 CVE Published
- 2024-12-05 CVE Updated
- 2024-12-09 First Exploit
- 2025-04-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A7497&LanguageCode=en&DocumentPartId=&Action=Launch |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/183448 | 2025-01-09 | |
https://packetstorm.news/files/id/183294 | 2024-12-24 | |
https://packetstorm.news/files/id/183027 | 2024-12-09 | |
https://packetstorm.news/files/id/183028 | 2024-12-09 | |
https://packetstorm.news/files/id/183032 | 2024-12-09 | |
https://packetstorm.news/files/id/183449 | 2025-01-09 | |
https://www.exploit-db.com/exploits/52217 | 2025-04-15 | |
https://www.exploit-db.com/exploits/52216 | 2025-04-15 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
ABB Search vendor "ABB" | ASPECT-Enterprise Search vendor "ABB" for product "ASPECT-Enterprise" | <= 3.08.02 Search vendor "ABB" for product "ASPECT-Enterprise" and version " <= 3.08.02" | en |
Affected
| ||||||
ABB Search vendor "ABB" | NEXUS Series Search vendor "ABB" for product "NEXUS Series" | <= 3.08.02 Search vendor "ABB" for product "NEXUS Series" and version " <= 3.08.02" | en |
Affected
| ||||||
ABB Search vendor "ABB" | MATRIX Series Search vendor "ABB" for product "MATRIX Series" | <= 3.08.02 Search vendor "ABB" for product "MATRIX Series" and version " <= 3.08.02" | en |
Affected
|