CVE-2025-53187
published 2025-08-11CVE-2025-53187: Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to…
PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.59%
44.8th percentile
Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | aspect | < <3.08.04-s01 | <3.08.04-s01 |
Detection & IOCsextracted from sources · hover to see the quote
- →Authentication bypass via debug code left in production firmware — monitor for unauthenticated requests that successfully change system time, access files, or invoke function calls on ABB ASPECT/NEXUS/MATRIX devices running firmware prior to 3.08.04-s01 ↗
- →Network-exploitable, no credentials required (PR:N, UI:N) — alert on anomalous unauthenticated HTTP/S sessions to ABB ASPECT BMS/BAS management interfaces from external or untrusted network segments ↗
- →Affected product families to fingerprint in network inventory: ABB ASPECT-Enterprise ASP-ENT-x, NEXUS Series NEX-2x, NEXUS Series NEXUS-3-x, MATRIX Series MAT-x — all versions prior to 3.08.04-s01 are vulnerable ↗
- ·Vulnerability is only exploitable if the ASPECT device is reachable from the attacker's network segment — exposure is eliminated if the device is not directly internet-facing and is placed behind a properly configured firewall/VPN ↗
- ·CVE-2025-53187 is fully remediated only in firmware version 3.08.04-s01 and later; all prior versions of ASPECT firmware remain vulnerable ↗
- ·Default credentials increase risk — if credentials were not changed during commissioning, the authentication bypass combined with unchanged defaults significantly widens the attack surface ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB Cylon Aspect BMS/BAS
cisa_ics·2025-09-09·CVSS 9.8
[CRITICAL] ABB Cylon Aspect BMS/BAS
ICS Advisory
##
ABB Cylon Aspect BMS/BAS
Release DateSeptember 09, 2025
Alert CodeICSA-25-252-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: ASPECT, NEXUS, MATRIX
- Vulnerabilities: Authentication Bypass Using an Alternate Path or Channel, Missing Authentication for Critical Function, Classic Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to assume control of the target device or perform a denial-of-service (DoS) attack.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
ABB reports that the following products are affec
GHSA
GHSA-xqxh-xcx3-fff7: Improper Control of Generation of Code ('Code Injection') vulnerability in ABB ASPECT
ghsa_unreviewed·2025-08-11
CVE-2025-53187 [HIGH] CWE-288 GHSA-xqxh-xcx3-fff7: Improper Control of Generation of Code ('Code Injection') vulnerability in ABB ASPECT
Improper Control of Generation of Code ('Code Injection') vulnerability in ABB ASPECT.This issue affects ASPECT: before <3.08.04-s01.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-11
Published