File Upload Vulnerabilities in ASPECT and NEXUS Series by ABB
CVE-2025-30169

6MEDIUM

Key Information:

Vendor

Abb

Vendor
CVE Published:
22 May 2025

What is CVE-2025-30169?

The vulnerability in ABB's ASPECT and NEXUS Series products allows malicious actors to exploit file upload functionality, potentially leading to PHP script injection if session administrator credentials are compromised. This poses significant security risks, enabling unauthorized execution of scripts within the affected systems. Organizations using versions of ASPECT-Enterprise, NEXUS Series, or MATRIX Series prior to 3.08.03 should take immediate action to mitigate this threat.

Affected Version(s)

ASPECT-Enterprise Linux 0 <= 3.08.03

MATRIX Series Linux 0 <= 3.08.03

NEXUS Series Linux 0 <= 3.08.03

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.