← Advisories

ABB Cylon Aspect 3.08.02 (MIX) Session Validation Bypass

High
Advisory ID
ZSL-2025-5938
Release Date
22 May 2025
Vendor
Affected Version
NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio, Firmware: <=3.08.02
CVE
N/A
Tested On
GNU/Linux 3.15.10 (armv7l), GNU/Linux 3.10.0 (x86_64), GNU/Linux 2.6.32 (x86_64), Intel(R) Atom(TM) Processor E3930 @ 1.30GHz, Intel(R) Xeon(R) Silver 4208 CPU @ 2.10GHz, PHP/7.3.11, PHP/5.6.30, PHP/5.4.16, PHP/4.4.8, PHP/5.3.3, AspectFT Automation Application Server, lighttpd/1.4.32, lighttpd/1.4.18, Apache/2.2.15 (CentOS), OpenJDK Runtime Environment (rhel-2.6.22.1.-x86_64), OpenJDK 64-Bit Server VM (build 24.261-b02, mixed mode), ErgoTech MIX Deployment Server 2.0.0
Summary

ASPECT is an award-winning scalable building energy management and control solution designed to allow users seamless access to their building data through standard building protocols including smart devices.

Description

ABB Cylon Aspect suffers from a broken session management issue. The backend implements inconsistent session validation by prioritizing the Authorization header over the PHPSESSID cookie, which is typically used to authenticate access to the controller system’s admin panel. While the PHPSESSID governs access to core configuration areas, the Authorization header acts as a second factor for authenticating against the HMI interface exposed on port 7226 by the mix.jar service. However, the system fails to enforce both factors simultaneously. If a client supplies a valid-looking Authorization header, access is granted, even in the absence of a valid PHPSESSID. This flaw breaks the expected session integrity model and allows an attacker to bypass proper authentication by forging or reusing the Authorization header alone, effectively nullifying multi-factor session enforcement.

Proof of Concept
Disclosure Timeline
21.04.2024Vulnerability discovered.
22.04.2024Vendor contacted.
22.04.2024Vendor responds.
02.05.2024Working with the vendor.
03.12.2024Vendor releases version 3.08.03 to address this issue.
22.05.2025Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
22.05.2025Initial release
26.05.2025Added reference [1]