Vulnerability Description
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abb | Aspect-Ent-12 Firmware | <= 3.08.01 |
| Abb | Aspect-Ent-12 | - |
| Abb | Aspect-Ent-2 Firmware | <= 3.08.01 |
| Abb | Aspect-Ent-2 | - |
| Abb | Aspect-Ent-256 Firmware | <= 3.08.01 |
| Abb | Aspect-Ent-256 | - |
| Abb | Aspect-Ent-96 Firmware | <= 3.08.01 |
| Abb | Aspect-Ent-96 | - |
| Abb | Nexus-2128 Firmware | <= 3.08.01 |
| Abb | Nexus-2128 | - |
| Abb | Nexus-2128-A Firmware | <= 3.08.01 |
| Abb | Nexus-2128-A | - |
| Abb | Nexus-2128-F Firmware | <= 3.08.01 |
| Abb | Nexus-2128-F | - |
| Abb | Nexus-2128-G Firmware | <= 3.08.01 |
| Abb | Nexus-2128-G | - |
| Abb | Nexus-264 Firmware | <= 3.08.01 |
| Abb | Nexus-264 | - |
| Abb | Nexus-264-A Firmware | <= 3.08.01 |
| Abb | Nexus-264-A | - |
Related Weaknesses (CWE)
References
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A7497&Language
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A7497&LanguageVendor Advisory
FAQ
What is CVE-2024-6298?
CVE-2024-6298 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
How severe is CVE-2024-6298?
CVE-2024-6298 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-6298?
Check the references section above for vendor advisories and patch information. Affected products include: Abb Aspect-Ent-12 Firmware, Abb Aspect-Ent-12, Abb Aspect-Ent-2 Firmware, Abb Aspect-Ent-2, Abb Aspect-Ent-256 Firmware.