CRITICAL
Authenticated Escalation to guest to root
Published May 22, 2025
9.5
CRITICALCVSS 4.0
EPSS 0.38%
Description
An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
Affected products
-
Affected
- ≥ 0, ≤ 3.08.03
-
Affected
- ≥ 0, ≤ 3.08.03
-
Affected
- ≥ 0, ≤ 3.08.03
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| ABB | ASPECT-Enterprise | affected | Affected
|
| ABB | MATRIX Series | unaffected | Affected
|
| ABB | NEXUS Series | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ABB
Published May 22, 2025
Updated May 22, 2025
Reserved Oct 8, 2024
Link CVE-2024-48853
CISA Vulnrichment
Updated May 22, 2025
Red Hat
No data
GitHub
No data