Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
The vulnerability results from insufficient protection of authentication data (CWE-522), which allows username enumeration at the application level. A network attacker, without any privileges and without user interaction, can gain access to the functions for adding, deleting, modifying, and listing user accounts. The lack of mechanisms blocking unauthorized access to these operations allows for complete manipulation of the system's user database.
An attacker can arbitrarily add, delete, modify, and view the list of user accounts in the system, leading to complete compromise of access management integrity and confidentiality. As a result, it is possible to take control of the building management system or destabilize it.
Apply patches available from the manufacturer in accordance with the references — ABB documentation with identifier 9AKK108469A7497 available at the address specified in the manufacturer's references.
ABB ASPECT - Enterprise v3.08.02, NEXUS Series v3.08.02, MATRIX Series v3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAbb Aspect Ent 12
HWAbball versionsAbb Aspect Ent 12 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2
HWAbball versionsAbb Aspect Ent 256
HWAbball versionsAbb Aspect Ent 256 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2 Firmware
OSAbb< 3.08.03Abb Aspect Ent 96
HWAbball versionsAbb Aspect Ent 96 Firmware
OSAbb< 3.08.03Abb Matrix 11
HWAbball versionsAbb Matrix 11 Firmware
OSAbb< 3.08.03Abb Matrix 216
HWAbball versionsAbb Matrix 216 Firmware
OSAbb< 3.08.03Abb Matrix 232
HWAbball versionsAbb Matrix 232 Firmware
OSAbb< 3.08.03Abb Matrix 264
HWAbball versionsAbb Matrix 264 Firmware
OSAbb< 3.08.03Abb Matrix 296
HWAbball versionsAbb Matrix 296 Firmware
OSAbb< 3.08.03Abb Nexus 2128
HWAbball versionsAbb Nexus 2128 A
HWAbball versionsAbb Nexus 2128 A Firmware
OSAbb< 3.08.03Abb Nexus 2128 F
HWAbball versionsAbb Nexus 2128 F Firmware
OSAbb< 3.08.03Abb Nexus 2128 Firmware
OSAbb< 3.08.03Abb Nexus 2128 G
HWAbball versionsAbb Nexus 2128 G Firmware
OSAbb< 3.08.03Abb Nexus 264
HWAbball versionsAbb Nexus 264 A
HWAbball versionsAbb Nexus 264 A Firmware
OSAbb< 3.08.03Abb Nexus 264 F
HWAbball versions
Related vulnerabilities
Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX
Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX
Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika
RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX
RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX