# CVE-2024-6298

## Summary

- **CVE ID:** CVE-2024-6298
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:I/V:C/RE:H/U:Red)
- **CWE:** CWE-1287
- **Published:** Jul 5, 2024
- **Last Modified:** Mar 13, 2026

## Description

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series

 v3.08.01

; MATRIX Series 

 v3.08.01 allows Attacker to execute arbitrary code remotely

## Affected Products

- ABB — ASPECT-Enterprise (0)
- ABB — NEXUS Series (0)
- ABB — MATRIX Series (0)

## References

- [CNA](https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A7497&LanguageCode=en&DocumentPartId=&Action=Launch)
- [CVE](https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A7497&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.39956449.23035250.1719878527-141379670.1701144964)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 19.01%
- **EPSS Percentile:** 97.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._