Missing Authentication for Critical Function in ABB Aspect
CVE-2025-7679

8.9HIGH

Key Information:

Vendor

Abb

Status
Vendor
CVE Published:
11 August 2025

What is CVE-2025-7679?

A vulnerability exists in ABB Aspect that allows unauthorized access to critical functions due to missing authentication checks. This weakness poses significant risks as attackers may exploit it to gain control over essential system capabilities, potentially leading to compromised security and unauthorized operations. Users and administrators are strongly encouraged to review their security configurations and apply necessary mitigation strategies to safeguard their systems.

Affected Version(s)

Aspect All versions

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB acknowledges Gjoko Krstikj, Zero Science Lab, for reporting vulnerabilities in responsible disclosure.
.
CVE-2025-7679 : Missing Authentication for Critical Function in ABB Aspect