CVE-2024-4008: FDSK Leak in KNX Secure Devices
Published Jun 5, 2024
·Updated
FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System
Affected Software
10 affected components
All of the following
ABB 2tma310010b0001 Firmware<1.02
ABB 2tma310010b0001
All of the following
ABB 2tma310011b0001 Firmware<1.02
ABB 2tma310011b0001
All of the following
ABB 2tma310011b0002 Firmware<1.02
ABB 2tma310011b0002
All of the following
ABB 2tma310010b0003 Firmware<1.02
ABB 2tma310010b0003
All of the following
ABB 2tma310011b0003 Firmware<1.02
ABB 2tma310011b0003
Event History
Jun 5, 2024
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4008?
CVE-2024-4008 is considered a critical vulnerability due to the potential for an attacker to take control of the affected systems.
2
How do I fix CVE-2024-4008?
To mitigate CVE-2024-4008, update the affected ABB devices to the latest firmware version 1.02 or higher.
3
What systems are affected by CVE-2024-4008?
CVE-2024-4008 affects ABB FTS Display version 1.00 and BCU version 1.3.0.33, along with specific 2TMA31001XX firmware versions.
4
Can CVE-2024-4008 be exploited remotely?
CVE-2024-4008 requires local access to the KNX Bus-System, making remote exploitation unlikely.
5
What are the potential impacts of CVE-2024-4008?
If exploited, CVE-2024-4008 can allow an attacker unauthorized control over the affected ABB devices.