ID

VAR-202505-2576


CVE

CVE-2024-9639


TITLE

ABB multiple products code injection vulnerability (CNVD-2025-13767)

Trust: 0.6

sources: CNVD: CNVD-2025-13767

DESCRIPTION

Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. ABB ASPECT-Enterprise is a scalable building energy management and control solution. ABB MATRIX Series is an embedded IoT ASPECT control engine designed to provide flexible field control for medium to large field control applications

Trust: 1.44

sources: NVD: CVE-2024-9639 // CNVD: CNVD-2025-13767

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-13767

AFFECTED PRODUCTS

vendor:abbmodel:aspect-enterprisescope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:nexus seriesscope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:matrix seriesscope:lteversion:<=3.08.03

Trust: 0.6

sources: CNVD: CNVD-2025-13767

CVSS

SEVERITY

CVSSV2

CVSSV3

cybersecurity@ch.abb.com: CVE-2024-9639
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-13767
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-13767
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:H/AU:M/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.2
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

cybersecurity@ch.abb.com: CVE-2024-9639
baseSeverity: HIGH
baseScore: 8.0
vectorString: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.3
impactScore: 6.0
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-13767 // NVD: CVE-2024-9639

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.0

sources: NVD: CVE-2024-9639

PATCH

title:Patch for ABB multiple products code injection vulnerability (CNVD-2025-13767)url:https://www.cnvd.org.cn/patchInfo/show/702271

Trust: 0.6

sources: CNVD: CNVD-2025-13767

EXTERNAL IDS

db:NVDid:CVE-2024-9639

Trust: 1.6

db:CNVDid:CNVD-2025-13767

Trust: 0.6

sources: CNVD: CNVD-2025-13767 // NVD: CVE-2024-9639

REFERENCES

url:https://search.abb.com/library/download.aspx?documentid=9akk108471a0021&languagecode=en&documentpartid=pdf&action=launch

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-9639

Trust: 0.6

sources: CNVD: CNVD-2025-13767 // NVD: CVE-2024-9639

SOURCES

db:CNVDid:CNVD-2025-13767
db:NVDid:CVE-2024-9639

LAST UPDATE DATE

2025-06-27T19:34:00.690000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-13767date:2025-06-26T00:00:00
db:NVDid:CVE-2024-9639date:2025-05-23T15:55:02.040

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-13767date:2025-06-26T00:00:00
db:NVDid:CVE-2024-9639date:2025-05-22T18:15:40.773