Aller au contenu

Fiche vulnérabilité

CVE-2023-0635 : faille critique abb aspect-ent-2 firmware (CVSS 9.8)

Description

Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
5 juin 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • abb aspect-ent-2 firmware
  • abb aspect-ent-12 firmware
  • abb aspect-ent-256 firmware
  • abb aspect-ent-96 firmware
  • abb nexus-2128 firmware
  • abb nexus-2128-a firmware
  • abb nexus-2128-g firmware
  • abb nexus-2128-f firmware
  • abb nexus-3-2128 firmware
  • abb nexus-3-264 firmware
  • abb nexus-264 firmware
  • abb nexus-264-a firmware
  • abb nexus-264-g firmware
  • abb nexus-264-f firmware
  • abb matrix-216 firmware
  • abb matrix-232 firmware
  • abb matrix-296 firmware
  • abb matrix-264 firmware
  • abb matrix-11 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE