The vendor explicitly identifies these products as affected by this CVE.
- ASP-ENT-x version<3.08.04-s01
- NEX-2x version <3.08.04-s01
- NEXUS-3-x version<3.08.04-s01
- MAT-x version <3.08.04-s01
- Summary
- The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT <3.08.04-s01
- Remediation
- No plans of corrective measures. The vulnerabilities reported in scope of this document are only exploitable if attackers can access the network segment where ASPECT is installed and exposed directly to the internet. ABB therefore recommends the following guidelines to protect customer networks: • ASPECT devices should never be exposed directly to the Internet either via a direct ISP connection nor via NAT port forwarding. If remote access to an ASPECT system is a customer requirement, the system shall operate behind a firewall. Users accessing ASPECT remotely shall do this using a VPN Gateway allowing access to the network segment where ASPECT is installed and configured • Note: it is crucial that the VPN Gateway and Network is set up in accordance with best industry standards and maintained in terms of security patches for all related components • Authorized users shall change all default credentials during commissioning of an ASPECT system. If credentials have not been changed during commission state, ABB advises to change each changeable credential at the earliest • Ensure that all ASPECT products are upgraded to the latest firmware version. Please find the latest version of ASPECT firmware on the respective product homepage
