vendor:
Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware <=4.00.00
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2024-XXXX (Not provided in the text)
CPE: a:abb_ltd:cylon_aspect:4.00.00
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 4.00.00 Unauthenticated XSS
The ABB Cylon Aspect BMS/BAS controller version 4.00.00 is vulnerable to unauthenticated reflected cross-site scripting (XSS) through the 'title' GET parameter. Attackers can execute malicious HTML/JS code in a user's browser within the context of the affected site.
Mitigation:
Ensure proper input validation and output encoding to prevent XSS attacks. Regularly update to the latest firmware version to patch known vulnerabilities.