Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
The vulnerability results from improper access control that allows an unauthorized network user to inject and execute malicious code (CWE-94 — Improper Control of Code Generation). An attacker can direct a specially crafted request to the device over the network without requiring any credentials. The attack vector is fully remote (AV:N), does not require complex conditions (AC:L), and requires no user interaction (UI:N).
An attacker can gain full control over a vulnerable device through remote code execution (RCE), leading to compromise of confidentiality and integrity of data processed by the building automation system. It is also possible to compromise the integrity of related systems and partial loss of device availability.
Security patches available from the manufacturer should be applied in accordance with references (ABB documentation: 9AKK108469A7497). It is recommended to immediately check the software version on all ASPECT, NEXUS and MATRIX devices and restrict network access to management panels exclusively to trusted hosts until updates are deployed.
ABB ASPECT - Enterprise version v3.08.02, ABB NEXUS Series version v3.08.02 and ABB MATRIX Series version v3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAbb Aspect Ent 12
HWAbball versionsAbb Aspect Ent 12 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2
HWAbball versionsAbb Aspect Ent 256
HWAbball versionsAbb Aspect Ent 256 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2 Firmware
OSAbb< 3.08.03Abb Aspect Ent 96
HWAbball versionsAbb Aspect Ent 96 Firmware
OSAbb< 3.08.03Abb Matrix 11
HWAbball versionsAbb Matrix 11 Firmware
OSAbb< 3.08.03Abb Matrix 216
HWAbball versionsAbb Matrix 216 Firmware
OSAbb< 3.08.03Abb Matrix 232
HWAbball versionsAbb Matrix 232 Firmware
OSAbb< 3.08.03Abb Matrix 264
HWAbball versionsAbb Matrix 264 Firmware
OSAbb< 3.08.03Abb Matrix 296
HWAbball versionsAbb Matrix 296 Firmware
OSAbb< 3.08.03Abb Nexus 2128
HWAbball versionsAbb Nexus 2128 A
HWAbball versionsAbb Nexus 2128 A Firmware
OSAbb< 3.08.03Abb Nexus 2128 F
HWAbball versionsAbb Nexus 2128 F Firmware
OSAbb< 3.08.03Abb Nexus 2128 Firmware
OSAbb< 3.08.03Abb Nexus 2128 G
HWAbball versionsAbb Nexus 2128 G Firmware
OSAbb< 3.08.03Abb Nexus 264
HWAbball versionsAbb Nexus 264 A
HWAbball versionsAbb Nexus 264 A Firmware
OSAbb< 3.08.03Abb Nexus 264 F
HWAbball versions
Related vulnerabilities
Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX
Enumeracja nazw użytkowników w ABB ASPECT, NEXUS i MATRIX Series
Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika
RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX
Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX