Headline
ABB Cylon Aspect 3.08.02 (deployStart.php) Unauthenticated Command Execution
The ABB Cylon Aspect BMS/BAS controller suffers from an unauthenticated shell command execution vulnerability through the deployStart.php script. This allows any user to trigger the execution of ‘rundeploy.sh’ script, which initializes the Java deployment server that sets various configurations, potentially causing unauthorized server initialization and performance issues.