ID

VAR-202505-3302


CVE

CVE-2025-30169


TITLE

ABB multiple product code issues vulnerability (CNVD-2025-13598)

Trust: 0.6

sources: CNVD: CNVD-2025-13598

DESCRIPTION

File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. ABB ASPECT-Enterprise is a scalable building energy management and control solution. ABB MATRIX Series is an embedded IoT ASPECT control engine designed to provide flexible field control for medium to large field control applications. ABB has a code issue vulnerability in many products that can be exploited by attackers to cause PHP script injection

Trust: 1.44

sources: NVD: CVE-2025-30169 // CNVD: CNVD-2025-13598

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-13598

AFFECTED PRODUCTS

vendor:abbmodel:aspect-enterprisescope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:nexus seriesscope:lteversion:<=3.08.03

Trust: 0.6

vendor:abbmodel:matrix seriesscope:lteversion:<=3.08.03

Trust: 0.6

sources: CNVD: CNVD-2025-13598

CVSS

SEVERITY

CVSSV2

CVSSV3

cybersecurity@ch.abb.com: CVE-2025-30169
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2025-13598
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-13598
severity: HIGH
baseScore: 8.0
vectorString: AV:N/AC:L/AU:M/C:P/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.4
impactScore: 9.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

cybersecurity@ch.abb.com: CVE-2025-30169
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.5
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-13598 // NVD: CVE-2025-30169

PROBLEMTYPE DATA

problemtype:CWE-434

Trust: 1.0

sources: NVD: CVE-2025-30169

PATCH

title:Patch for ABB multiple product code issues vulnerability (CNVD-2025-13598)url:https://www.cnvd.org.cn/patchInfo/show/702266

Trust: 0.6

sources: CNVD: CNVD-2025-13598

EXTERNAL IDS

db:NVDid:CVE-2025-30169

Trust: 1.6

db:CNVDid:CNVD-2025-13598

Trust: 0.6

sources: CNVD: CNVD-2025-13598 // NVD: CVE-2025-30169

REFERENCES

url:https://search.abb.com/library/download.aspx?documentid=9akk108471a0021&languagecode=en&documentpartid=pdf&action=launch

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2025-30169

Trust: 0.6

sources: CNVD: CNVD-2025-13598 // NVD: CVE-2025-30169

SOURCES

db:CNVDid:CNVD-2025-13598
db:NVDid:CVE-2025-30169

LAST UPDATE DATE

2025-06-27T23:13:48.496000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-13598date:2025-06-26T00:00:00
db:NVDid:CVE-2025-30169date:2025-05-23T15:55:02.040

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-13598date:2025-06-26T00:00:00
db:NVDid:CVE-2025-30169date:2025-05-22T18:15:41.443