First published: Mon Jun 05 2023(Updated: )
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.
Credit: cybersecurity@ch.abb.com cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Abb Aspect-ent-2 Firmware | >=3.0.0<3.07.01 | |
Abb Aspect-ent-2 | ||
Abb Aspect-ent-12 Firmware | >=3.0.0<3.07.01 | |
Abb Aspect-ent-12 | ||
Abb Aspect-ent-256 Firmware | >=3.0.0<3.07.01 | |
Abb Aspect-ent-256 | ||
Abb Aspect-ent-96 Firmware | >=3.0.0<3.07.01 | |
Abb Aspect-ent-96 | ||
Abb Nexus-2128 Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-2128 | ||
Abb Nexus-2128-a Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-2128-a | ||
Abb Nexus-2128-g Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-2128-g | ||
Abb Nexus-2128-f Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-2128-f | ||
Abb Nexus-3-2128 Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-3-2128 | ||
Abb Nexus-3-264 Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-3-264 | ||
Abb Nexus-264 Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-264 | ||
Abb Nexus-264-a Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-264-a | ||
Abb Nexus-264-g Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-264-g | ||
Abb Nexus-264-f Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-264-f | ||
Abb Matrix-216 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-216 | ||
Abb Matrix-232 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-232 | ||
Abb Matrix-296 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-296 | ||
Abb Matrix-264 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-264 | ||
Abb Matrix-11 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-11 | ||
All of | ||
Abb Aspect-ent-2 | ||
Abb Aspect-ent-2 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Aspect-ent-12 | ||
Abb Aspect-ent-12 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Aspect-ent-256 | ||
Abb Aspect-ent-256 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Aspect-ent-96 | ||
Abb Aspect-ent-96 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-2128 | ||
Abb Nexus-2128 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-2128-a | ||
Abb Nexus-2128-a Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-2128-g | ||
Abb Nexus-2128-g Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-2128-f | ||
Abb Nexus-2128-f Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-3-2128 | ||
Abb Nexus-3-2128 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-3-264 | ||
Abb Nexus-3-264 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-264 | ||
Abb Nexus-264 Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-264-a | ||
Abb Nexus-264-a Firmware | >=3.0.0<3.07.01 | |
All of | ||
Abb Nexus-264-g Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-264-g | ||
All of | ||
Abb Nexus-264-f Firmware | >=3.0.0<3.07.01 | |
Abb Nexus-264-f | ||
All of | ||
Abb Matrix-216 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-216 | ||
All of | ||
Abb Matrix-232 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-232 | ||
All of | ||
Abb Matrix-296 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-296 | ||
All of | ||
Abb Matrix-264 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-264 | ||
All of | ||
Abb Matrix-11 Firmware | >=3.0.0<3.07.01 | |
Abb Matrix-11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0635 is an Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux and ABB Ltd. NEXUS Series on NEXUS Series, Linux.
CVE-2023-0635 has a severity rating of critical with a CVSS score of 9.8.
CVE-2023-0635 affects ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux versions 3.0.0 to 3.07.01 and ABB Ltd. NEXUS Series on NEXUS Series, Linux versions 3.0.0 to 3.07.01.
To fix CVE-2023-0635, update ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux to version 3.07.01 or later, and update ABB Ltd. NEXUS Series on NEXUS Series, Linux to version 3.07.01 or later.
You can find more information about CVE-2023-0635 in the [ABB Security Advisory document](https://search.abb.com/library/Download.aspx?DocumentID=2CKA000073B5403&LanguageCode=en&DocumentPartId=&Action=Launch).