<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:28:01 +0000</lastBuildDate>
    <item>
      <title>9AKK108471A4462 — ELSB/BLBA ASPECT advisory several CVEs</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108471a4462</link>
      <description>&lt;p&gt;ABB became aware of vulnerabilities in ASPECT product versions listed as affected in the advisory. The earliest report dates to June 2023. ABB has fixed most of the vulnerabilities reported. At the moment there are no plans of corrective measures for remaining vulnerabilities in the affected products.
ASPECT is an on-premise Building Management System (BMS) that provides an additional option to be remotely accessible. In order to support customers’ demand for cloud connectivity, ABB has decided to replace ASPECT and will introduce customers to a new solution based on the latest Industry level cyber security standards. The new solution will bring HW and SW capabilities that reflect state-of-the-art technology and is delivered including a maintenance plan that offers customers the best planning security.
Customers who have concerns about continuing the operation of ASPECT may contact ABB sales service to become advised about further support options.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB became aware of vulnerabilities in ASPECT product versions listed as affected in the advisory. The earliest report dates to June 2023. ABB has fixed most of the vulnerabilities reported. At the moment there are no plans of corrective measures for remaining vulnerabilities in the affected products.
ASPECT is an on-premise Building Management System (BMS) that provides an additional option to be remotely accessible. In order to support customers’ demand for cloud connectivity, ABB has decided to replace ASPECT and will introduce customers to a new solution based on the latest Industry level cyber security standards. The new solution will bring HW and SW capabilities that reflect state-of-the-art technology and is delivered including a maintenance plan that offers customers the best planning security.
Customers who have concerns about continuing the operation of ASPECT may contact ABB sales service to become advised about further support options.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108471a4462</guid>
    </item>
    <item>
      <title>EUVD-2026-252158</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252158</link>
      <description>EUVD-2026-252158</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252158</guid>
    </item>
    <item>
      <title>fkie_cve-2025-7677</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-7677</link>
      <description>&lt;p&gt;A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue that may lead to a software crash. 
This issue affects all versions of ASPECT.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue that may lead to a software crash. 
This issue affects all versions of ASPECT.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-7677</guid>
    </item>
    <item>
      <title>GHSA-6x2w-49fq-p52h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6x2w-49fq-p52h</link>
      <description>&lt;p&gt;Missing Authentication for Critical Function vulnerability in ABB Aspect.This issue affects Aspect: All versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authentication for Critical Function vulnerability in ABB Aspect.This issue affects Aspect: All versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6x2w-49fq-p52h</guid>
    </item>
    <item>
      <title>ICSA-25-252-02 — ABB Cylon Aspect BMS/BAS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-252-02</link>
      <description>&lt;p&gt;Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01. A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue that may lead to a software crash. This issue affects all versions of ASPECT. The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior authentication. This issue affects all versions of ASPECT prior to 3.08.04-s01. A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue that may lead to a software crash. This issue affects all versions of ASPECT. The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-252-02</guid>
    </item>
  </channel>
</rss>
