CVE-2023-0635: Privilege escalation to root
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0635?
CVE-2023-0635 is an Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux and ABB Ltd. NEXUS Series on NEXUS Series, Linux.
How severe is CVE-2023-0635?
CVE-2023-0635 has a severity rating of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2023-0635?
CVE-2023-0635 affects ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux versions 3.0.0 to 3.07.01 and ABB Ltd. NEXUS Series on NEXUS Series, Linux versions 3.0.0 to 3.07.01.
How do I fix CVE-2023-0635?
To fix CVE-2023-0635, update ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux to version 3.07.01 or later, and update ABB Ltd. NEXUS Series on NEXUS Series, Linux to version 3.07.01 or later.
Where can I find more information about CVE-2023-0635?
You can find more information about CVE-2023-0635 in the [ABB Security Advisory document](https://search.abb.com/library/Download.aspx?DocumentID=2CKA000073B5403&LanguageCode=en&DocumentPartId=&Action=Launch).