CVE-2024-13954: Serialization / Deserialization of configuration data
Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13954?
CVE-2024-13954 has a medium severity rating due to potential disclosure of sensitive configuration information.
How do I fix CVE-2024-13954?
To fix CVE-2024-13954, update to the latest versions of ASPECT-Enterprise, NEXUS Series, or MATRIX Series beyond version 3.*.
What are the affected products of CVE-2024-13954?
CVE-2024-13954 affects ASPECT-Enterprise, NEXUS Series, and MATRIX Series, all versions up to 3.*.
What type of vulnerability is CVE-2024-13954?
CVE-2024-13954 is a configuration disclosure vulnerability that may expose serialized configuration information.
During what process does CVE-2024-13954 occur?
CVE-2024-13954 occurs during the device commissioning process while using ASPECT's configuration toolset.