ID

VAR-202505-3719


CVE

CVE-2024-13928


TITLE

ABB products have SQL injection vulnerabilities (CNVD-2025-13770)

Trust: 0.6

sources: CNVD: CNVD-2025-13770

DESCRIPTION

SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. ABB ASPECT-Enterprise is a scalable building energy management and control solution. ABB MATRIX Series is an embedded IoT ASPECT control engine designed to provide flexible field control for medium to large field control applications

Trust: 1.44

sources: NVD: CVE-2024-13928 // CNVD: CNVD-2025-13770

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-13770

AFFECTED PRODUCTS

vendor:abbmodel:aspect-enterprisescope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:nexus seriesscope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:matrix seriesscope:lteversion:<=3.08.03

Trust: 0.6

sources: CNVD: CNVD-2025-13770

CVSS

SEVERITY

CVSSV2

CVSSV3

cybersecurity@ch.abb.com: CVE-2024-13928
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-13770
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-13770
severity: HIGH
baseScore: 8.3
vectorString: AV:N/AC:L/AU:M/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

cybersecurity@ch.abb.com: CVE-2024-13928
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-13770 // NVD: CVE-2024-13928

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.0

sources: NVD: CVE-2024-13928

PATCH

title:Patch for ABB products have SQL injection vulnerabilities (CNVD-2025-13770)url:https://www.cnvd.org.cn/patchInfo/show/702286

Trust: 0.6

sources: CNVD: CNVD-2025-13770

EXTERNAL IDS

db:NVDid:CVE-2024-13928

Trust: 1.6

db:CNVDid:CNVD-2025-13770

Trust: 0.6

sources: CNVD: CNVD-2025-13770 // NVD: CVE-2024-13928

REFERENCES

url:https://search.abb.com/library/download.aspx?documentid=9akk108471a0021&languagecode=en&documentpartid=pdf&action=launch

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-13928

Trust: 0.6

sources: CNVD: CNVD-2025-13770 // NVD: CVE-2024-13928

SOURCES

db:CNVDid:CNVD-2025-13770
db:NVDid:CVE-2024-13928

LAST UPDATE DATE

2025-06-27T23:15:32.104000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-13770date:2025-06-26T00:00:00
db:NVDid:CVE-2024-13928date:2025-05-23T15:55:02.040

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-13770date:2025-06-26T00:00:00
db:NVDid:CVE-2024-13928date:2025-05-22T18:15:39.310