vendor:
Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Cylon Aspect
Affected Version From: 03.08.02
Affected Version To: 03.08.02
Patch Exists: NO
Related CWE: CVE-2024-48839, CVE-2024-6516, CVE-2024-51550
CPE: a:abb_ltd:cylon_aspect:3.08.02
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) – Remote Code Execution
The ABB Cylon Aspect BMS/BAS controller in version 3.08.02 and below is vulnerable to an authenticated blind command injection. Attackers can execute arbitrary shell commands by manipulating input in certain POST parameters. Additionally, an off-by-one error in array access can result in undefined behavior and potential Denial of Service (DoS) attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to update the ABB Cylon Aspect BMS/BAS controller to a version that includes a patch addressing the command injection and array access issues.