📦 Matrix 296 Firmware

by Abb

🔍 What is Matrix 296 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-51547

CRITICAL CVSS 9.8 Feb 6, 2025

This CVE describes a use of hard-coded credentials vulnerability in multiple ABB industrial control system products. Attackers can use these embedded credentials to gain unauthorized access to affecte...

CVE-2024-6515

CRITICAL CVSS 9.6 Dec 5, 2024

This vulnerability in ABB industrial control system web interfaces exposes authentication credentials in clear text or Base64 encoding during transmission. Attackers can intercept these credentials to...

CVE-2024-6784

CRITICAL CVSS 9.9 Dec 5, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in ABB industrial control system products that allows attackers to make the server send unauthorized requests to internal or exter...

CVE-2024-51548

CRITICAL CVSS 9.9 Dec 5, 2024

CVE-2024-51548 is a dangerous unrestricted file upload vulnerability in ABB ASPECT, NEXUS, and MATRIX series products that allows attackers to upload malicious scripts. If exploited, this could lead t...

CVE-2024-51550

CRITICAL CVSS 10.0 Dec 5, 2024

This CVE describes a data validation/sanitization vulnerability in ABB ASPECT industrial control system devices that allows injection of unvalidated data. Attackers could potentially execute arbitrary...

CVE-2024-51554

CRITICAL CVSS 9.1 Dec 5, 2024

CVE-2024-51554 is a default credential vulnerability in ABB ASPECT products on Linux that allows attackers to gain unauthorized access using publicly known default credentials. This affects ABB ASPECT...

CVE-2024-51545

CRITICAL CVSS 10.0 Dec 5, 2024

This CVE describes a username enumeration vulnerability in ABB industrial control system products that allows attackers to access user management functions. Attackers can add, delete, modify, and list...

CVE-2024-48839

CRITICAL CVSS 10.0 Dec 5, 2024

This critical vulnerability in ABB ASPECT, NEXUS, and MATRIX series allows remote attackers to execute arbitrary code on affected systems by sending specially crafted input. It affects industrial cont...

CVE-2024-48845

CRITICAL CVSS 9.4 Dec 5, 2024

This CVE describes weak password reset rules in ABB building automation systems that allow storage of weak passwords, potentially enabling unauthorized administrative or application access. Affected s...

CVE-2024-11317

CRITICAL CVSS 10.0 Dec 5, 2024

CVE-2024-11317 is a session fixation vulnerability in ABB ASPECT, NEXUS, and MATRIX series products that allows attackers to set a user's session ID before authentication, enabling session hijacking a...

CVE-2024-6209

CRITICAL CVSS 10.0 Jul 5, 2024

This vulnerability allows attackers to access files without authorization in ABB ASPECT-Enterprise, NEXUS Series, and MATRIX Series web servers. It affects all systems running version 3.08.01 of these...

CVE-2024-48847

HIGH CVSS 8.2 Dec 5, 2024

This vulnerability allows attackers to bypass MD5 checksum validation in ABB industrial control systems, potentially enabling malicious code execution or unauthorized modifications. It affects ABB ASP...

CVE-2024-51542

HIGH CVSS 8.2 Dec 5, 2024

This CVE allows attackers to download configuration files containing dependency information from ABB industrial control systems. This affects ABB ASPECT-Enterprise, NEXUS Series, and MATRIX Series ver...

CVE-2024-51544

HIGH CVSS 8.2 Dec 5, 2024

This vulnerability in ABB's Service Control allows attackers to access service restart requests and virtual machine configuration settings. It affects ABB ASPECT-Enterprise, NEXUS Series, and MATRIX S...

CVE-2024-48843

HIGH CVSS 7.7 Dec 5, 2024

This CVE describes a Denial of Service vulnerability in ABB's ASPECT, NEXUS, and MATRIX series products. Attackers can exploit this vulnerability to cause service disruptions in affected industrial co...

CVE-2024-11316

HIGH CVSS 7.5 Dec 5, 2024

This CVE describes a file size check vulnerability in ABB ASPECT, NEXUS, and MATRIX series products that allows attackers to bypass file size limits. This could lead to resource exhaustion or unexpect...

CVE-2024-4007

HIGH CVSS 8.8 Jul 1, 2024

This vulnerability involves default credentials in ABB ASPECT, NEXUS, and MATRIX Series version 3.07 install packages. Attackers can exploit this to log into product instances that have been incorrect...

CVE-2023-0635

HIGH CVSS 7.8 Jun 5, 2023

This CVE describes an improper privilege management vulnerability in ABB's ASPECT-Enterprise, NEXUS Series, and MATRIX Series products running on Linux. It allows authenticated attackers to escalate p...