ABB Cylon Aspect version 3.08.01 is vulnerable to unauthorized SSH service configuration changes via the jsonProxy.php endpoint. An unauthenticated attacker can enable or disable the SSH service on the server by accessing the FTControlServlet with the sshenable parameter. The jsonProxy.php script proxies requests to localhost without enforcing...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2388142
💾 ABB Cylon Aspect 3.08.01 jsonProxy.php Unauthenticated Remote SSH Service Control
⏱️ vor 639d 21h (30.10.2024 um 16:31 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com