CVE-2024-13946
Severity CVSS v4.0:
HIGH
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
22/05/2025
Last modified:
23/05/2025
Description
DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.80
Severity 3.x
MEDIUM