CVE-2024-48847

HIGH

ABB Aspect-ent-2 Firmware < 3.08.03 - Broken Cryptographic Algorithm

Title source: rule
STIX 2.1

Description

MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products: ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRIX Series v3.08.01

Scores

CVSS v3 8.2
EPSS 0.0007
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-327 CWE-328
Status published
Products (19)
abb/aspect-ent-12_firmware < 3.08.01
abb/aspect-ent-256_firmware < 3.08.03
abb/aspect-ent-2_firmware < 3.08.03
abb/aspect-ent-96_firmware < 3.08.03
abb/matrix-11_firmware < 3.08.01
abb/matrix-216_firmware < 3.08.01
abb/matrix-232_firmware < 3.08.01
abb/matrix-264_firmware < 3.08.01
abb/matrix-296_firmware < 3.08.01
abb/nexus-2128-a_firmware < 3.08.03
... and 9 more
Published Dec 05, 2024
Tracked Since Feb 18, 2026