RULE(RULE ID:338898)

Rule General Information
Release Date: 2025-05-14
Rule Name: ABB Cylon Aspect 4.00.00 Remote Code Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: ABB Cylon Aspect is a smart building software launched by ABB, which is used to integrate and manage HVAC, lighting, security and other systems in buildings, achieving efficient and energy-saving intelligent building operations. ABB Cylon Aspect 4.00.00 version has a remote command execution vulnerability, which allows attackers to execute arbitrary commands by sending specially crafted messages to trigger the vulnerability.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.