CVE-2025-30173Unrestricted File Upload in Aspect-enterprise

Severity
6.0MEDIUMNVD
EPSS
0.3%
top 50.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22

Description

File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/S:N

Affected Packages3 packages

CVEListV5abb/nexus_series3.08.03
CVEListV5abb/matrix_series3.08.03
CVEListV5abb/aspect-enterprise3.08.03

🔴Vulnerability Details

2
GHSA
GHSA-qg6w-c843-2xjm: File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: throug2025-05-22
CVEList
Admin Authorized File Upload2025-05-22
CVE-2025-30173 — Unrestricted File Upload in ABB | cvebase