CVE-2024-13954
Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
- EPSS probability
- 0.22%
- CWE
- CWE-922
- Published
- 2025-05-22
- Last modified
- 2026-03-13
Affected products
- ABB ASPECT-Enterprise
- ABB NEXUS Series
- ABB MATRIX Series
Weakness type
Related vulnerabilities
- CVE-2026-44629 — Improper access control to the Synergis Softwire installation folder. This vulnerability affects...
- CVE-2026-20705 — Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform...
- CVE-2026-47362 — The Datadog Android application stores operationally sensitive content in plaintext SQLite...
- CVE-2026-46511 — HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2025-32751 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2025-32746 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2026-7257 — ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the...
- CVE-2026-40868 — kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token