CVE-2023-0635 Details
Description
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| abb aspect-ent-2 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb aspect-ent-2 | All versions |
CPE
Remediation
| |
| abb aspect-ent-12 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb aspect-ent-12 | All versions |
CPE
Remediation
| |
| abb aspect-ent-256 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb aspect-ent-256 | All versions |
CPE
Remediation
| |
| abb aspect-ent-96 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb aspect-ent-96 | All versions |
CPE
Remediation
| |
| abb nexus-2128 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-2128 | All versions |
CPE
Remediation
| |
| abb nexus-2128-a firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-2128-a | All versions |
CPE
Remediation
| |
| abb nexus-2128-g firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-2128-g | All versions |
CPE
Remediation
| |
| abb nexus-2128-f firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-2128-f | All versions |
CPE
Remediation
| |
| abb nexus-3-2128 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-3-2128 | All versions |
CPE
Remediation
| |
| abb nexus-3-264 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-3-264 | All versions |
CPE
Remediation
| |
| abb nexus-264 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-264 | All versions |
CPE
Remediation
| |
| abb nexus-264-a firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-264-a | All versions |
CPE
Remediation
| |
| abb nexus-264-g firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-264-g | All versions |
CPE
Remediation
| |
| abb nexus-264-f firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb nexus-264-f | All versions |
CPE
Remediation
| |
| abb matrix-216 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb matrix-216 | All versions |
CPE
Remediation
| |
| abb matrix-232 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb matrix-232 | All versions |
CPE
Remediation
| |
| abb matrix-296 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb matrix-296 | All versions |
CPE
Remediation
| |
| abb matrix-264 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb matrix-264 | All versions |
CPE
Remediation
| |
| abb matrix-11 firmware | >= 3.0.0, < 3.07.01 |
CPE
Remediation
| |
| abb matrix-11 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 19, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Jun 13, 2023 | Initial Analysis | [email protected] |