Vulnerability Description
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abb | Aspect-Ent-2 Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Aspect-Ent-2 | - |
| Abb | Aspect-Ent-12 Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Aspect-Ent-12 | - |
| Abb | Aspect-Ent-256 Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Aspect-Ent-256 | - |
| Abb | Aspect-Ent-96 Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Aspect-Ent-96 | - |
| Abb | Nexus-2128 Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Nexus-2128 | - |
| Abb | Nexus-2128-A Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Nexus-2128-A | - |
| Abb | Nexus-2128-G Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Nexus-2128-G | - |
| Abb | Nexus-2128-F Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Nexus-2128-F | - |
| Abb | Nexus-3-2128 Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Nexus-3-2128 | - |
| Abb | Nexus-3-264 Firmware | >= 3.0.0, < 3.07.01 |
| Abb | Nexus-3-264 | - |
Related Weaknesses (CWE)
References
- https://search.abb.com/library/Download.aspx?DocumentID=2CKA000073B5403&LanguageVendor Advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2CKA000073B5403&LanguageVendor Advisory
FAQ
What is CVE-2023-0635?
CVE-2023-0635 is a vulnerability with a CVSS score of 7.8 (HIGH). Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Ser...
How severe is CVE-2023-0635?
CVE-2023-0635 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0635?
Check the references section above for vendor advisories and patch information. Affected products include: Abb Aspect-Ent-2 Firmware, Abb Aspect-Ent-2, Abb Aspect-Ent-12 Firmware, Abb Aspect-Ent-12, Abb Aspect-Ent-256 Firmware.