CVE-2025-53187

CRITICAL

ASPECT <3.08.04-s01 - Auth Bypass

Title source: llm
STIX 2.1

Description

Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
ABB/ASPECT < <3.08.04-s01
Published Aug 11, 2025
Tracked Since Feb 18, 2026