ABB ASPECT-Enterprise
cpe:2.3:h:abb:aspect-ent-12:*:*:*:*:*:*:*, +7 more
- <= 3.*
A vulnerability exists in ABB's ASPECT-Enterprise, NEXUS Series, and MATRIX Series applications, all through version 3.*, due to DLLs not being digitally signed when loaded in the ASPECT configuration toolset. This oversight exposes the application to binary planting attacks during device commissioning.
Exploitation of this vulnerability could lead to binary planting, allowing malicious DLLs to be loaded by the application, potentially leading to arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.