CVE-2016-2307 is a critical vulnerability affecting American Auto-Matrix Aspect-Nexus and Aspect-Matrix Building Automation Front-End Solutions applications prior to version 3.0.0. This flaw allows remote attackers to read arbitrary files, including sensitive configuration files, through unspecified vectors. With a CVSS score of 7.5 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high confidentiality impact, requiring no user interaction or privileges. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:american_auto-matrix:aspect-matrix_building_automation_front-end_solutions_application:-:*:*:*:*:*:*:* | ||
<= 2.0CPE matchmatch criteria | cpe:2.3:a:american_auto-matrix:aspect-nexus_building_automation_front-end_solutions_application:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.