vendor:
ABB Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Authenticated Path Traversal
22
CWE
Product Name: ABB Cylon Aspect
Affected Version From: 03.08.02
Affected Version To: 03.08.02
Patch Exists: NO
Related CWE:
CPE: a:abb_ltd:cylon_aspect:3.08.02
Platforms Tested: GNU/Linux, Intel processors, PHP versions, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.02 Authenticated Path Traversal
The ABB Cylon controller in the version 3.08.02 and below is vulnerable to an authenticated path traversal issue. By manipulating the 'devName' POST parameter in ethernetUpdate.php script, an attacker can write partially controlled data like IP addresses to arbitrary file paths. This could potentially result in unauthorized configuration changes, system compromise, and denial of service by overwriting ethernet configuration backup files.
Mitigation:
To mitigate this vulnerability, it is recommended to update the ABB Cylon controller firmware to a version higher than 3.08.02. Additionally, restrict access to the ethernetUpdate.php script to authorized personnel only.