vendor:
ASPECT
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ASPECT
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware <=3.08.02
Affected Version To: 03.08.02
Patch Exists: YES
Related CWE: CVE-2024-48839
CPE: a:abb_ltd:aspect:3.08.02
Platforms Tested: GNU/Linux, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.02 – Remote Code Execution
The ABB Cylon Aspect BMS/BAS controller before 3.08.02 is vulnerable to authenticated OS command injection. Attackers can upload a specially crafted .db file that contains malicious shell commands. These commands are then executed on the server through the copyFile.sh script, bypassing filename sanitization.
Mitigation:
Update to the latest firmware version (3.08.03 or later) to patch this vulnerability. Additionally, sanitize user inputs and validate uploaded files to prevent arbitrary command injection.