- Description
- Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01
- Source
- cybersecurity@ch.abb.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- cybersecurity@ch.abb.com
- CWE-288
- Hype score
- Not currently trending
🚨Alert🚨CVE-2025-53187(CVSS 9.8): Critical RCE Vulnerability in ABB ASPECT https://t.co/A0xTdSPWK9 Prior Authentication 📊1.1K Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link:https://t.co/wx1uv1yCWt 👇Query HUNTER : https://t.co/q9rtuGfZuz="ABB
@HunterMapping
8 Sept 2025
1966 Impressions
8 Retweets
23 Likes
8 Bookmarks
2 Replies
0 Quotes
🚨🚨ABB ASPECT BMS Flaws Exposed CVE-2025-53187 (CVSS 9.8): Debug code allows auth bypass, enabling RCE, file access, & system time manipulation. CVE-2025-7679 (CVSS 8.1): Session ID flaw lets attackers skip authentication. CVE-2025-7677 (CVSS 5.9): Buffer issue causes D
@zoomeye_team
5 Sept 2025
487 Impressions
1 Retweet
2 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2025-53187 Improper Control of Generation of Code ('Code Injection') vulnerability in ABB ASPECT.This issue affects ASPECT: before <3.08.04-s01. https://t.co/SywhYTJyEO
@CVEnew
11 Aug 2025
244 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes