CVE-2023-0636: Remote Code Execution via Command Injection
Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Command Injection.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.0; NEXUS Series: from 3.0;0 before 3.07.0; MATRIX Series: from 3.0;0 before 3.07.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this ABB Ltd. ASPECT®-Enterprise vulnerability?
The vulnerability ID is CVE-2023-0636.
What is the severity level of CVE-2023-0636?
The severity level of CVE-2023-0636 is critical with a score of 9.8.
Which software products are affected by CVE-2023-0636?
ABB Ltd. ASPECT®-Enterprise and ABB Ltd. NEXUS Series on ASPECT®-Enterprise, Linux, and NEXUS Series firmware versions 3.0.0 to 3.07.01 are affected.
How can I fix CVE-2023-0636?
Apply the latest firmware update provided by ABB Ltd. to address CVE-2023-0636.
Where can I find more information about CVE-2023-0636?
You can find more information about CVE-2023-0636 at the following link: [https://search.abb.com/library/Download.aspx?DocumentID=2CKA000073B5403&LanguageCode=en&DocumentPartId=&Action=Launch](https://search.abb.com/library/Download.aspx?DocumentID=2CKA000073B5403&LanguageCode=en&DocumentPartId=&Action=Launch)