Security
Headlines
HeadlinesLatestCVEs

Headline

ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) Authenticated Path Traversal

The ABB Cylon controller suffers from an authenticated path traversal vulnerability. This can be exploited through the ‘devName’ POST parameter in the ethernetUpdate.php script to write partially controlled content, such as IP address values, into arbitrary file paths, potentially leading to configuration tampering and system compromise including denial of service scenario through ethernet configuration backup file overwrite.

Zero Science Lab
#vulnerability#dos#php#auth

Zero Science Lab: Latest News

ABB Cylon Aspect 3.08.02 (deployStart.php) Unauthenticated Command Execution