← Vulnerability feed

Vulnerability record · CVE-2024-51544 · published 5 December 2024

CVE-2024-51544: Abb aspect-ent-12 firmware vulnerability

Abb · Aspect Ent 12 Firmware

Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

8.8 CVSS 4.0 High EPSS 13% · top 3.7% CWE-15 · CWE-15
8.8CVSS 4.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
19Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-51544 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-0636Abb aspect-ent-2 firmware command injection vulnerabilityImproper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S302…EPSS 1.4%9.8CVE-2023-0635Abb aspect-ent-2 firmware vulnerabilityImproper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203…EPSS 0.37%9.4CVE-2024-6209Abb aspect-ent-12 firmware vulnerabilityUnauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access …EPSS 17%9.4CVE-2024-6298Abb aspect-ent-12 firmware vulnerabilityUnauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute…EPSS 19%9.3CVE-2024-51547Abb aspect-ent-2 firmware hard-coded credentials vulnerabilityUse of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: throu…EPSS 0.62%9.3CVE-2024-6516Abb aspect-ent-2 firmware cross-site scripting vulnerabilityCross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products…EPSS 1.1%9.3CVE-2024-51549Abb aspect-ent-12 firmware path traversal vulnerabilityAbsolute File Traversal vulnerabilities allows access and modification of un-intended resources.  Affected products: ABB ASPECT - Enterprise v3.08.02…EPSS 0.54%9.3CVE-2024-51550Abb aspect-ent-12 firmware vulnerabilityData Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.  Affected pr…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2024-51544), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.