vendor:
Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Arbitrary File Deletion
22
CWE
Product Name: Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware <=3.08.01
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2024-6209
CPE: a:abb_ltd:aspect_firmware:3.08.01
Platforms Tested: GNU/Linux, Intel Processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK
2024
ABB Cylon Aspect 3.08.01 – Arbitrary File Delete
The ABB Cylon Aspect version 3.08.01 allows an unauthenticated attacker to delete files with web server permissions through directory traversal sequences in the 'file' parameter of 'databasefiledelete.php'. This vulnerability could be exploited to delete critical files.
Mitigation:
Ensure input validation and proper sanitization of user-supplied data to prevent directory traversal attacks. Regularly update to the latest firmware version provided by the vendor.