vendor:
Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Remote Code Execution (RCE)
22
CWE
Product Name: Cylon Aspect
Affected Version From: 03.08.01
Affected Version To: 03.08.01
Patch Exists: NO
Related CWE: CVE-2024-6298
CPE: a:abb_ltd:cylon_aspect:3.08.01
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK
Not specified
ABB Cylon Aspect 3.08.01 – Remote Code Execution (RCE)
The ABB Cylon Aspect version 3.08.01 and below is vulnerable to remote code execution. The issue arises due to the improper handling of user input in the uploadFile() function of bigUpload.php. This vulnerability allows an attacker to upload malicious files to arbitrary locations on the server, leading to arbitrary code execution. An authenticated attacker can exploit this to gain unauthorized access to the building controller.
Mitigation:
To mitigate this vulnerability, it is recommended to update the ABB Cylon Aspect firmware to a version above 3.08.01. Additionally, input validation and proper handling of user-supplied data should be implemented to prevent such remote code execution attacks.