Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
The vulnerability stems from lack of proper input validation of data supplied over the network to control software components (CWE-94 — Code Injection). An attacker can send specially crafted input data that will be improperly processed by the application and result in arbitrary code execution on the device side. The attack vector is network-based (AV:N), requires no authentication (PR:N) or user interaction (UI:N), which means the attack can be conducted fully remotely without any prior privileges.
An attacker can gain full control of the device by executing arbitrary code with its privileges, which may lead to breach of confidentiality and integrity of processed data as well as disruption of building management systems or industrial automation operations.
Apply patches available from the manufacturer according to references (ABB documentation with identifier 9AKK108469A7497). It is recommended to deploy updates as soon as possible and restrict network access to devices only from trusted hosts until the patch is applied.
ABB ASPECT - Enterprise v3.08.02, ABB NEXUS Series v3.08.02, ABB MATRIX Series v3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAbb Aspect Ent 12
HWAbball versionsAbb Aspect Ent 12 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2
HWAbball versionsAbb Aspect Ent 256
HWAbball versionsAbb Aspect Ent 256 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2 Firmware
OSAbb< 3.08.03Abb Aspect Ent 96
HWAbball versionsAbb Aspect Ent 96 Firmware
OSAbb< 3.08.03Abb Matrix 11
HWAbball versionsAbb Matrix 11 Firmware
OSAbb< 3.08.03Abb Matrix 216
HWAbball versionsAbb Matrix 216 Firmware
OSAbb< 3.08.03Abb Matrix 232
HWAbball versionsAbb Matrix 232 Firmware
OSAbb< 3.08.03Abb Matrix 264
HWAbball versionsAbb Matrix 264 Firmware
OSAbb< 3.08.03Abb Matrix 296
HWAbball versionsAbb Matrix 296 Firmware
OSAbb< 3.08.03Abb Nexus 2128
HWAbball versionsAbb Nexus 2128 A
HWAbball versionsAbb Nexus 2128 A Firmware
OSAbb< 3.08.03Abb Nexus 2128 F
HWAbball versionsAbb Nexus 2128 F Firmware
OSAbb< 3.08.03Abb Nexus 2128 Firmware
OSAbb< 3.08.03Abb Nexus 2128 G
HWAbball versionsAbb Nexus 2128 G Firmware
OSAbb< 3.08.03Abb Nexus 264
HWAbball versionsAbb Nexus 264 A
HWAbball versionsAbb Nexus 264 A Firmware
OSAbb< 3.08.03Abb Nexus 264 F
HWAbball versions
Related vulnerabilities
Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX
Enumeracja nazw użytkowników w ABB ASPECT, NEXUS i MATRIX Series
Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika
RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX
Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX