ABB Cylon Aspect 3.08.01 jsonProxy.php Denial Of Service

Discussion in 'News Aggregator' started by Packet Storm, 31 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    ABB Cylon Aspect version 3.08.01 is vulnerable to an unauthenticated denial of service attack in the jsonProxy.php endpoint. An attacker can remotely restart the main Java server by accessing the FTControlServlet with the restart parameter. The endpoint proxies requests to localhost without requiring authentication, enabling attackers to disrupt system availability by repeatedly triggering server restarts.

    Continue reading...
     

Share This Page

Loading...