vendor:
Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware: <=3.08.02
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2024-48846
CPE: abb:aspect:3.08.02
Platforms Tested: GNU/Linux, Intel Processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK
2024
ABB Cylon Aspect 3.08.02 Cross-Site Request Forgery
The ABB Cylon Aspect 3.08.02 allows attackers to perform unauthorized actions with administrative privileges by sending malicious HTTP requests to the userManagement.php script. This vulnerability exists due to the lack of proper validation checks on incoming requests, enabling attackers to exploit the system through a logged-in user visiting a malicious website.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and authentication mechanisms. Regular security audits and monitoring for unusual activities can also help detect and prevent CSRF attacks.