CVE-2025-30170 MEDIUM

CVE-2025-30170: Admin Authorized Exposure of file path, file size or file existence

Vendor Abb
Product ASPECT-Enterprise
Weakness CWE-497
Published May 22, 2025
Last update May 22, 2025

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:C

What the vulnerability does

01Description

Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

Key dates

02Disclosure timeline

May 22, 2025 CVE published
May 22, 2025 Record updated