vendor:
ASPECT Building Energy Management and Control Solution
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Arbitrary Content Injection
20
CWE
Product Name: ASPECT Building Energy Management and Control Solution
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware version 3.08.03 and below
Affected Version To: 03.08.03
Patch Exists: NO
Related CWE:
CPE: h:abb:ltd:aspect_firmware:3.08.03
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) File Write Denial of Service (DoS)
The ABB Cylon Aspect BMS/BAS controller through webServerDeviceLabelUpdate.php script allows authenticated attackers to inject arbitrary content via the 'deviceLabel' POST parameter, leading to writing content to a fixed file location (/usr/local/aam/etc/deviceLabel) and potentially causing denial of service.
Mitigation:
Ensure proper input validation on the 'deviceLabel' parameter to prevent arbitrary content injection. Regularly update to the latest firmware version provided by ABB Ltd.