An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
The vulnerability classified as CWE-286 (Incorrect User Management) involves improper verification of user permissions within the ASPECT platform. An attacker with a non-root account can exploit this flaw to escalate their privileges and gain full administrative access to the server. The vulnerability does not require user interaction or special prerequisites beyond having access to an account in the system.
An attacker can gain full root access to the server, enabling system control takeover, data reading and modification, malicious software installation, and further lateral movement in the network.
Apply patches available from the manufacturer according to references (ABB documentation number 9AKK108471A0021). It is recommended to restrict access to ASPECT systems exclusively to authorized users and monitor privilege escalation attempts.
ABB ASPECT-Enterprise in versions up to and including 3.08.03; ABB NEXUS Series in versions up to and including 3.08.03; ABB MATRIX Series in versions up to and including 3.08.03.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:X/U:X