vendor:
                    Cylon Aspect
                by:
                    Gjoko 'LiquidWorm' Krstic
                6.1
                        CVSS
                    HIGH
                    Remote Code Execution
                    78
                        CWE
                    Product Name: Cylon Aspect
                    Affected Version From:  03.08.02
                    Affected Version To:  03.08.02
                    Patch Exists: NO
                    Related CWE: CVE-2024-48839, CVE-2024-6516, CVE-2024-51550
                    CPE:  a:abb_ltd:cylon_aspect:3.08.02
                    Platforms Tested:  GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
                    2024
                    ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) – Remote Code Execution
The ABB Cylon Aspect BMS/BAS controller in version 3.08.02 and below is vulnerable to an authenticated blind command injection. Attackers can execute arbitrary shell commands by manipulating input in certain POST parameters. Additionally, an off-by-one error in array access can result in undefined behavior and potential Denial of Service (DoS) attacks.
Mitigation:
					To mitigate this vulnerability, it is recommended to update the ABB Cylon Aspect BMS/BAS controller to a version that includes a patch addressing the command injection and array access issues.