Description
DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
Problem types
CWE-427 Uncontrolled Search Path Element
Product status
Any version
Any version
Any version
Credits
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
References
search.abb.com/...geCode=en&DocumentPartId=pdf&Action=Launch