vendor:
ABB Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Hard-coded Credentials
798
CWE
Product Name: ABB Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware <=3.08.03
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: abb:cylon_aspect:3.08.03
Platforms Tested: GNU/Linux, Intel Processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.03 Hard-coded Secrets
The ABB Cylon Aspect BMS/BAS controller has hard-coded credentials such as usernames, passwords, and encryption keys in various java classes. This vulnerability could be exploited by attackers to gain unauthorized access and compromise system integrity.
Mitigation:
To mitigate this issue, it is recommended to update to a patched version that removes the hard-coded credentials and perform regular security audits to ensure no sensitive information is stored in plain text within the application.