vendor:
ABB Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
File Disclosure
22
CWE
Product Name: ABB Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware: <=3.07.02
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:abb_ltd:cylon_aspect:3.07.02
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK
2024
ABB Cylon Aspect 3.07.02 – File Disclosure
The ABB Cylon Aspect 3.07.02 product is prone to an authenticated arbitrary file disclosure vulnerability. This vulnerability exists in the 'downloadDb.php' script due to improper validation of user-supplied input in the 'file' GET parameter. Attackers can exploit this issue to read sensitive files by traversing directories.
Mitigation:
To mitigate this vulnerability, restrict access to the affected script and ensure that user input is properly validated and sanitized before use.