vendor:
ASPECT
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Session Fixation
384
CWE
Product Name: ASPECT
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware: <=3.08.02
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2024-11317
CPE: a:abb_ltd:aspect:3.08.02
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.02 PHP Session Fixation Vulnerability
The ABB Cylon Aspect BMS/BAS controller is vulnerable to session fixation, allowing an attacker to set a predefined PHPSESSID value. This can be exploited by leveraging an unauthenticated reflected XSS vulnerability in jsonProxy.php to inject a crafted request, forcing the victim to adopt a fixated session.
Mitigation:
To mitigate this vulnerability, users should ensure that the software is updated to the latest version available from the vendor. Additionally, it is recommended to restrict access to the affected systems and implement proper input validation mechanisms.