CVE-2024-13946
DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- Affected products
- Aspect-Enterprise, Matrix Series, Nexus Series
- Fix
- Available
- CVSS 4.0
- 7.1 HIGH
- CVSS 3.1
- 6.8 MEDIUM
- EPSS
- 1.0% (61th percentile)
- Weakness
- CWE-427
- NVD status
- Deferred
- Published
- 2025-05-22
CVE-2024-13946 at NVD
3 known exploits for CVE-2024-13946
Proof-of-concept code and exploit modules indexed by Sploitus