Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
An error in data input classification or validation (CWE-1287) in the WEB server of ABB ASPECT products allows an attacker to gain unauthorized access to system files without authentication. By exploiting this vulnerability, an attacker operating in the same network segment can upload or read files in a way that enables remote code execution (RCE) on the vulnerable device.
An attacker can remotely execute arbitrary code on the device without possessing any privileges, gaining full control over the building management system and potentially over the associated network infrastructure.
Patches available from the manufacturer should be applied according to the references. Detailed information about updates is available in the ABB document with identifier 9AKK108469A7497. Additionally, it is recommended to restrict network access to the WEB interface exclusively to trusted network segments and implement network segmentation for ASPECT devices.
ABB ASPECT - Enterprise version v3.08.01, ABB NEXUS Series version v3.08.01, ABB MATRIX Series version v3.08.01 (including products Aspect-Ent-12, Aspect-Ent-2, Aspect-Ent-256 and their firmware).
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:I/V:C/RE:H/U:RedAbb Aspect Ent 12
HWAbball versionsAbb Aspect Ent 12 Firmware
OSAbb≤ 3.08.01Abb Aspect Ent 2
HWAbball versionsAbb Aspect Ent 256
HWAbball versionsAbb Aspect Ent 256 Firmware
OSAbb≤ 3.08.01Abb Aspect Ent 2 Firmware
OSAbb≤ 3.08.01Abb Aspect Ent 96
HWAbball versionsAbb Aspect Ent 96 Firmware
OSAbb≤ 3.08.01Abb Matrix 11
HWAbball versionsAbb Matrix 11 Firmware
OSAbb≤ 3.08.01Abb Matrix 216
HWAbball versionsAbb Matrix 216 Firmware
OSAbb≤ 3.08.01Abb Matrix 232
HWAbball versionsAbb Matrix 232 Firmware
OSAbb≤ 3.08.01Abb Matrix 264
HWAbball versionsAbb Matrix 264 Firmware
OSAbb≤ 3.08.01Abb Matrix 296
HWAbball versionsAbb Matrix 296 Firmware
OSAbb≤ 3.08.01Abb Nexus 2128
HWAbball versionsAbb Nexus 2128 A
HWAbball versionsAbb Nexus 2128 A Firmware
OSAbb≤ 3.08.01Abb Nexus 2128 F
HWAbball versionsAbb Nexus 2128 F Firmware
OSAbb≤ 3.08.01Abb Nexus 2128 Firmware
OSAbb≤ 3.08.01Abb Nexus 2128 G
HWAbball versionsAbb Nexus 2128 G Firmware
OSAbb≤ 3.08.01Abb Nexus 264
HWAbball versionsAbb Nexus 264 A
HWAbball versionsAbb Nexus 264 A Firmware
OSAbb≤ 3.08.01Abb Nexus 264 F
HWAbball versions
Related vulnerabilities
Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX
Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX
Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika
RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX
RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX