vendor:
Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Unauthenticated Command Execution
78
CWE
Product Name: Cylon Aspect
Affected Version From: Before 3.08.02
Affected Version To: 03.08.02
Patch Exists: NO
Related CWE: CVE-2024-48840
CPE: abb:cylon_aspect_firmware
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.02 Unauthenticated Command Execution
The ABB Cylon Aspect BMS/BAS controller before 3.08.02 allows unauthenticated users to execute arbitrary shell commands via the deployStart.php script. This vulnerability can be exploited to run the 'rundeploy.sh' script, which initializes the Java deployment server and configures settings, leading to unauthorized server initialization and potential performance issues.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict access to the deployStart.php script and ensure that only authenticated users can execute commands. Additionally, applying the vendor-supplied patches or updates that address this issue is crucial.