vendor:
                    ASPECT
                by:
                    Gjoko 'LiquidWorm' Krstic
                6.1
                        CVSS
                    HIGH
                    Remote Code Execution
                    78
                        CWE
                    Product Name: ASPECT
                    Affected Version From:  NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware <=3.08.02
                    Affected Version To:  03.08.02
                    Patch Exists: YES
                    Related CWE: CVE-2024-48839
                    CPE:  a:abb_ltd:aspect:3.08.02
                    Platforms Tested:  GNU/Linux, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
                    2024
                    ABB Cylon Aspect 3.08.02 – Remote Code Execution
The ABB Cylon Aspect BMS/BAS controller before 3.08.02 is vulnerable to authenticated OS command injection. Attackers can upload a specially crafted .db file that contains malicious shell commands. These commands are then executed on the server through the copyFile.sh script, bypassing filename sanitization.
Mitigation:
					Update to the latest firmware version (3.08.03 or later) to patch this vulnerability. Additionally, sanitize user inputs and validate uploaded files to prevent arbitrary command injection.