CVE-2023-0636
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Command Injection.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.0; NEXUS Series: from 3.0;0 before 3.07.0; MATRIX Series: from 3.0;0 before 3.07.1.
Affected (19)
Products: Abb: Aspect Ent 2 Firmware, Aspect Ent 12 Firmware, Aspect Ent 256 Firmware, Aspect Ent 96 Firmware, Nexus 2128 Firmware, Nexus 2128 A Firmware, Nexus 2128 G Firmware, Nexus 2128 F Firmware, Nexus 3 2128 Firmware, Nexus 3 264 Firmware, Nexus 264 Firmware, Nexus 264 A Firmware, Nexus 264 G Firmware, Nexus 264 F Firmware, Matrix 216 Firmware, Matrix 232 Firmware, Matrix 296 Firmware, Matrix 264 Firmware, Matrix 11 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 12 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 256 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Aspect Ent 96 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 A | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 G | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 2128 F | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 3 2128 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 3 264 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 A | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 G | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Nexus 264 F | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 216 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 232 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 296 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 264 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0.0 to 3.07.01 |
| Running on/with | Platform Versions |
|---|---|
Abb Matrix 11 | All versions |
References (2)
Source: cybersecurity@ch.abb.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.