CVE-2025-53187

CRITICAL

ABB ASPECT < 3.08.04-s01 - Unauthenticated Authentication Bypass via Debug Code

Title source: llm
STIX 2.1

Description

Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01

Scores

CVSS v3 9.8
EPSS 0.0056
EPSS Percentile 41.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
ABB/ASPECT < <3.08.04-s01
Published Aug 11, 2025
Tracked Since Feb 18, 2026