Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
The vulnerability results from the lack of appropriate validation and sanitization of input data (CWE-1287) in the Linux system that forms the basis of ABB ASPECT device software. A remote attacker, without authentication and without any user interaction, can deliver specially crafted data that will be accepted and processed by the device. The absence of input data control mechanisms allows their injection into the logic of the running system.
An attacker can gain unauthorized access to device data and affect the integrity of processed information, which in a building automation systems environment can lead to disruption of infrastructure operation. The CVSS vector indicates a high impact on the confidentiality and integrity of device data.
Patches available from the manufacturer should be applied according to references – detailed information is available in the ABB document number 9AKK108469A7497 at the address indicated in the references.
ABB ASPECT - Enterprise version 3.08.02, NEXUS Series version 3.08.02, MATRIX Series version 3.08.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAbb Aspect Ent 12
HWAbball versionsAbb Aspect Ent 12 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2
HWAbball versionsAbb Aspect Ent 256
HWAbball versionsAbb Aspect Ent 256 Firmware
OSAbb< 3.08.03Abb Aspect Ent 2 Firmware
OSAbb< 3.08.03Abb Aspect Ent 96
HWAbball versionsAbb Aspect Ent 96 Firmware
OSAbb< 3.08.03Abb Matrix 11
HWAbball versionsAbb Matrix 11 Firmware
OSAbb< 3.08.03Abb Matrix 216
HWAbball versionsAbb Matrix 216 Firmware
OSAbb< 3.08.03Abb Matrix 232
HWAbball versionsAbb Matrix 232 Firmware
OSAbb< 3.08.03Abb Matrix 264
HWAbball versionsAbb Matrix 264 Firmware
OSAbb< 3.08.03Abb Matrix 296
HWAbball versionsAbb Matrix 296 Firmware
OSAbb< 3.08.03Abb Nexus 2128
HWAbball versionsAbb Nexus 2128 A
HWAbball versionsAbb Nexus 2128 A Firmware
OSAbb< 3.08.03Abb Nexus 2128 F
HWAbball versionsAbb Nexus 2128 F Firmware
OSAbb< 3.08.03Abb Nexus 2128 Firmware
OSAbb< 3.08.03Abb Nexus 2128 G
HWAbball versionsAbb Nexus 2128 G Firmware
OSAbb< 3.08.03Abb Nexus 264
HWAbball versionsAbb Nexus 264 A
HWAbball versionsAbb Nexus 264 A Firmware
OSAbb< 3.08.03Abb Nexus 264 F
HWAbball versions
Related vulnerabilities
Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX
Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX
Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika
RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX
RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX