CVE-2025-7679

7.4

ABB · ASPECT

The ABB ASPECT system contains a missing authentication vulnerability that allows unauthenticated users to bypass security controls and access critical functions.

Executive summary

A critical authentication bypass vulnerability in the ABB ASPECT system allows unauthenticated attackers to gain unauthorized access to critical functions, posing a severe risk to operational integrity.

Vulnerability

This vulnerability involves a missing authentication for a critical function (CWE-306). It allows an unauthenticated attacker to interact with sensitive system processes without providing valid credentials.

Business impact

The ability for an unauthenticated user to bypass authentication mechanisms creates a significant risk of unauthorized command execution and system compromise. Given the CVSS score of 7.4, this vulnerability represents a high-severity threat that could lead to full control over affected ASPECT systems, potentially resulting in operational disruption or the manipulation of industrial control processes.

Remediation

Immediate Action: Review the official ABB security advisory provided in the reference link and apply all available security updates or configuration changes recommended by the vendor.

Proactive Monitoring: Monitor network access logs for anomalous traffic directed at the ASPECT system and implement strict network segmentation to limit exposure to untrusted networks.

Compensating Controls: Deploy a Web Application Firewall or industrial-grade firewall to filter traffic and restrict unauthorized access to the affected management interfaces until the system can be fully patched.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of authentication bypass vulnerabilities in industrial systems, organizations must treat this flaw with high urgency. Administrators should verify their current version of ABB ASPECT against the vendor's updated guidance and ensure that the system is isolated from public internet access wherever possible to prevent exploitation.

More ABB CVEs

Sources

Originally found and disclosed by ABB acknowledges Gjoko Krstikj, Zero Science Lab, for reporting vulnerabilities in responsible disclosure., per the CVE Program record.