CVE-2024-13954 DetailsANALYZED This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.
Description Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
A vulnerability exists in ABB's ASPECT-Enterprise, NEXUS Series, and MATRIX Series products, all through version 3.*, allowing for the unintentional disclosure of serialized configuration information during device commissioning. This issue arises while using ASPECT's configuration toolset.
Show AI summary Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 22, 2025 Exploitation: NoneAutomatable: —Technical Impact: Partial
CISA-ADP
Assessed May 22, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration Affected Products Product Versions ABB ASPECT-Enterprise <= 3.*
CPE cpe:2.3:h:abb:aspect-ent-12:*:*:*:*:*:*:*:* cpe:2.3:h:abb:aspect-ent-2:*:*:*:*:*:*:*:* cpe:2.3:h:abb:aspect-ent-256:*:*:*:*:*:*:*:* cpe:2.3:h:abb:aspect-ent-96:*:*:*:*:*:*:*:* cpe:2.3:o:abb:aspect-ent-12_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:aspect-ent-256_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:aspect-ent-2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:aspect-ent-96_firmware:*:*:*:*:*:*:*:* Remediation No remediation found in references. ABB NEXUS <= 3.*
CPE cpe:2.3:h:abb:nexus-2128:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-2128-a:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-2128-f:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-2128-g:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-264:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-264-a:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-264-f:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-264-g:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-3-2128:*:*:*:*:*:*:*:* cpe:2.3:h:abb:nexus-3-264:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-2128-a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-2128-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-2128_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-2128-g_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-264-a_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-264-f_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-264_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-264-g_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-3-2128_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:nexus-3-264_firmware:*:*:*:*:*:*:*:* Remediation No remediation found in references. ABB MATRIX All versions
CPE cpe:2.3:h:abb:matrix-11:*:*:*:*:*:*:*:* cpe:2.3:h:abb:matrix-216:*:*:*:*:*:*:*:* cpe:2.3:h:abb:matrix-232:*:*:*:*:*:*:*:* cpe:2.3:h:abb:matrix-264:*:*:*:*:*:*:*:* cpe:2.3:h:abb:matrix-296:*:*:*:*:*:*:*:* cpe:2.3:o:abb:matrix-11_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:matrix-216_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:matrix-232_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:matrix-264_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:abb:matrix-296_firmware:*:*:*:*:*:*:*:* Remediation No remediation found in references.
Change History 3 change records found show changes