Where
-Infinity
0
Severity
10
EPSS
0.50%
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
10
EPSS
0.32%
Code Injection, Input Validation
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Improper Input Validation vulnerability allows Remote Code Execution.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
10
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Absolute File Traversal vulnerabilities allows access and modification of un-intended resources.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
9.9
Malicious File Upload
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
9.8
EPSS
0.12%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.  Affected products:

ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

First published (updated )
Severity
9.6
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
9.5
AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
9.3
XSS
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
9.1
EPSS
0.03%
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products:

ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRIX Series v3.08.01

First published (updated )
Severity
9.1
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
9.1
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
9
AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H

System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
8.9
Code Injection
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
8.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Information Disclosure vulnerabilities allow access to application configuration information.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
8.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
8.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
8.8
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..

First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
8.7
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
8.7
Code Injection
AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..

First published (updated )
Severity
8.4
Path Traversal
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials become compromised.

This issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..

First published (updated )
Severity
8
Code Injection
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
7.7
EPSS
0.16%
AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
7.7
EPSS
0.07%
SQL Injection
AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:

ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

First published (updated )
Severity
7.6
SSRF
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..

First published (updated )
Severity
7.5
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
7.5
Code Injection, SQL Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
7.5
Path Traversal
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )
Severity
7.5
Code Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203