Fiche vulnérabilité
CVE-2023-0635 : faille critique abb aspect-ent-2 firmware (CVSS 9.8)
Description
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 5 juin 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- abb aspect-ent-2 firmware
- abb aspect-ent-12 firmware
- abb aspect-ent-256 firmware
- abb aspect-ent-96 firmware
- abb nexus-2128 firmware
- abb nexus-2128-a firmware
- abb nexus-2128-g firmware
- abb nexus-2128-f firmware
- abb nexus-3-2128 firmware
- abb nexus-3-264 firmware
- abb nexus-264 firmware
- abb nexus-264-a firmware
- abb nexus-264-g firmware
- abb nexus-264-f firmware
- abb matrix-216 firmware
- abb matrix-232 firmware
- abb matrix-296 firmware
- abb matrix-264 firmware
- abb matrix-11 firmware