CVE-2025-30170

MEDIUM

ABB ASPECT-Enterprise, NEXUS Series, MATRIX Series <= 3.08.03 - Authenticated Exposure of Sensitive System Information

Title source: llm
STIX 2.1

Description

Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (3)
ABB/ASPECT-Enterprise < 3.08.03
ABB/MATRIX Series < 3.08.03
ABB/NEXUS Series < 3.08.03
Published May 22, 2025
Tracked Since Feb 18, 2026