Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:NMEDIUM: 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:NDefault status
affected
Any version
affected
Default status
unaffected
Any version
affected
Default status
unaffected
Any version
affected
Description
Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation
Product status
Any version
Any version
Any version
Credits
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
References
search.abb.com/...geCode=en&DocumentPartId=pdf&Action=Launch