vendor:
ASPECT
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: ASPECT
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware <=3.08.03
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, ErgoTech MIX Deployment Server
2024
ABB Cylon Aspect 3.08.03 (CookieDB) SQL Injection
The ABB Cylon Aspect 3.08.03 BMS/BAS controller is vulnerable to SQL injection through the key and user parameters, as they are not properly sanitized. This allows attackers to manipulate SQL queries, potentially leading to unauthorized access to the database or execution of arbitrary SQL commands.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user inputs, utilize parameterized queries, and implement proper access controls. Regular security updates and monitoring can also help prevent SQL injection attacks.