CVE-2024-51550

CRITICAL

ABB ASPECT Enterprise, NEXUS Series, and MATRIX Series <3.08.02 <3 - Data Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-51550.

AI-analyzed exploit summary The exploit demonstrates a blind command injection vulnerability in ABB Cylon Aspect's bbmdUpdate.php. It leverages unsanitized POST parameters (e.g., hexMask2, NAThexMask2) to inject shell commands (e.g., 'sleep 17') via authenticated HTTP requests.

Description

Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Exploits (1)

exploitdb WORKING POC
pocmultiple
https://www.exploit-db.com/exploits/52217

The exploit demonstrates a blind command injection vulnerability in ABB Cylon Aspect's bbmdUpdate.php. It leverages unsanitized POST parameters (e.g., hexMask2, NAThexMask2) to inject shell commands (e.g., 'sleep 17') via authenticated HTTP requests.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ABB Cylon Aspect (Firmware <= 3.08.02)
Auth required
Prerequisites: Valid PHPSESSID cookie for authentication · Network access to the target device
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0179
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1287
Status published
Products (19)
abb/aspect-ent-12_firmware < 3.08.03
abb/aspect-ent-256_firmware < 3.08.03
abb/aspect-ent-2_firmware < 3.08.03
abb/aspect-ent-96_firmware < 3.08.03
abb/matrix-11_firmware < 3.08.03
abb/matrix-216_firmware < 3.08.03
abb/matrix-232_firmware < 3.08.03
abb/matrix-264_firmware < 3.08.03
abb/matrix-296_firmware < 3.08.03
abb/nexus-2128-a_firmware < 3.08.03
... and 9 more
Published Dec 05, 2024
Tracked Since Feb 18, 2026