ABB Cylon Aspect 3.08.01 networkDiagAjax.php Remote Network Utility Execution

Discussion in 'News Aggregator' started by Packet Storm, 18 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    ABB Cylon Aspect version 3.08.01 allows an unauthenticated attacker to perform network operations such as ping, traceroute, or nslookup on arbitrary hosts or IPs by sending a crafted GET request to networkDiagAjax.php. This could be exploited to interact with or probe internal or external systems, leading to internal information disclosure and misuse of network resources.

    Continue reading...
     

Share This Page

Loading...