CVE-2024-13947: External System or Configuration Control
Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13947?
The severity of CVE-2024-13947 is considered critical due to the potential for unauthorized modification of device commissioning parameters.
How do I fix CVE-2024-13947?
To fix CVE-2024-13947, update the affected ASPECT-Enterprise, NEXUS Series, or MATRIX Series software to the latest version that addresses this vulnerability.
Which products are affected by CVE-2024-13947?
CVE-2024-13947 affects ASPECT-Enterprise versions through 3.*, NEXUS Series through 3.*, and MATRIX Series through 3.*.
What can happen if CVE-2024-13947 is exploited?
If CVE-2024-13947 is exploited, an attacker could modify device commissioning parameters, potentially leading to unauthorized access and control of the affected devices.
Is there a workaround for CVE-2024-13947?
A temporary workaround for CVE-2024-13947 includes implementing strict access controls and monitoring for any unauthorized changes until a patch is applied.