Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
The attack involves an attacker first obtaining or imposing a specific session identifier (session ID) before the victim logs into the system. If the application does not generate a new session identifier after successful authentication, the attacker — knowing the previously established session ID — can use it as their own, fully authenticated session. The attack is possible remotely, without authentication and without server-side interaction, which significantly lowers the threshold for its execution.
An attacker can hijack the session of a logged-in user and gain unauthorized access to the system with their privileges, which may lead to unauthorized reading and modification of data in building management systems controlled by vulnerable devices.
Security patches available from the manufacturer should be applied according to references (ABB documentation with identifier 9AKK108469A7497). It is recommended to update the firmware to a version newer than 3.08.02 as soon as it becomes available from the manufacturer.
ABB ASPECT - Enterprise version 3.08.02, NEXUS Series version 3.08.02, MATRIX Series version 3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAbb Aspect Ent 12
HWAbball versionsAbb Aspect Ent 12 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2
HWAbball versionsAbb Aspect Ent 256
HWAbball versionsAbb Aspect Ent 256 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2 Firmware
OSAbb< 3.08.03Abb Aspect Ent 96
HWAbball versionsAbb Aspect Ent 96 Firmware
OSAbb< 3.08.03Abb Matrix 11
HWAbball versionsAbb Matrix 11 Firmware
OSAbb< 3.08.03Abb Matrix 216
HWAbball versionsAbb Matrix 216 Firmware
OSAbb< 3.08.03Abb Matrix 232
HWAbball versionsAbb Matrix 232 Firmware
OSAbb< 3.08.03Abb Matrix 264
HWAbball versionsAbb Matrix 264 Firmware
OSAbb< 3.08.03Abb Matrix 296
HWAbball versionsAbb Matrix 296 Firmware
OSAbb< 3.08.03Abb Nexus 2128
HWAbball versionsAbb Nexus 2128 A
HWAbball versionsAbb Nexus 2128 A Firmware
OSAbb< 3.08.03Abb Nexus 2128 F
HWAbball versionsAbb Nexus 2128 F Firmware
OSAbb< 3.08.03Abb Nexus 2128 Firmware
OSAbb< 3.08.03Abb Nexus 2128 G
HWAbball versionsAbb Nexus 2128 G Firmware
OSAbb< 3.08.03Abb Nexus 264
HWAbball versionsAbb Nexus 264 A
HWAbball versionsAbb Nexus 264 A Firmware
OSAbb< 3.08.03Abb Nexus 264 F
HWAbball versions
Related vulnerabilities
Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX
Enumeracja nazw użytkowników w ABB ASPECT, NEXUS i MATRIX Series
RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX
RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX
Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX