ID

VAR-202505-4267


CVE

CVE-2024-13931


TITLE

Path traversal vulnerabilities in multiple ABB products

Trust: 0.6

sources: CNVD: CNVD-2025-13768

DESCRIPTION

Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. ABB ASPECT-Enterprise is a scalable building energy management and control solution. ABB MATRIX Series is an embedded IoT ASPECT control engine designed to provide flexible field control for medium to large field control applications

Trust: 1.44

sources: NVD: CVE-2024-13931 // CNVD: CNVD-2025-13768

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-13768

AFFECTED PRODUCTS

vendor:abbmodel:aspect-enterprisescope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:nexus seriesscope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:matrix seriesscope:lteversion:<=3.08.03

Trust: 0.6

sources: CNVD: CNVD-2025-13768

CVSS

SEVERITY

CVSSV2

CVSSV3

cybersecurity@ch.abb.com: CVE-2024-13931
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-13768
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-13768
severity: HIGH
baseScore: 8.3
vectorString: AV:N/AC:L/AU:M/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

cybersecurity@ch.abb.com: CVE-2024-13931
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-13768 // NVD: CVE-2024-13931

PROBLEMTYPE DATA

problemtype:CWE-606

Trust: 1.0

sources: NVD: CVE-2024-13931

PATCH

title:Patch for Path traversal vulnerabilities in multiple ABB productsurl:https://www.cnvd.org.cn/patchInfo/show/702276

Trust: 0.6

sources: CNVD: CNVD-2025-13768

EXTERNAL IDS

db:NVDid:CVE-2024-13931

Trust: 1.6

db:CNVDid:CNVD-2025-13768

Trust: 0.6

sources: CNVD: CNVD-2025-13768 // NVD: CVE-2024-13931

REFERENCES

url:https://search.abb.com/library/download.aspx?documentid=9akk108471a0021&languagecode=en&documentpartid=pdf&action=launch

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-13931

Trust: 0.6

sources: CNVD: CNVD-2025-13768 // NVD: CVE-2024-13931

SOURCES

db:CNVDid:CNVD-2025-13768
db:NVDid:CVE-2024-13931

LAST UPDATE DATE

2025-06-27T23:11:39.347000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-13768date:2025-06-26T00:00:00
db:NVDid:CVE-2024-13931date:2025-05-23T15:55:02.040

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-13768date:2025-06-26T00:00:00
db:NVDid:CVE-2024-13931date:2025-05-22T18:15:40.117