Use of Hard-coded Credentials in ABB ASPECT-Enterprise, NEXUS Series, and MATRIX Series
CVE-2024-51547

9.3CRITICAL

Key Information:

Vendor

Abb

Vendor
CVE Published:
6 February 2025

What is CVE-2024-51547?

A significant security vulnerability exists in several ABB products including ASPECT-Enterprise, NEXUS Series, and MATRIX Series due to the use of hard-coded credentials. This issue can lead to unauthorized access, potentially compromising the integrity and confidentiality of sensitive data. Affected versions include ASPECT-Enterprise and both NEXUS and MATRIX Series up to version 3.08.03. It is crucial for users to update their systems to mitigate the risks associated with this vulnerability.

Affected Version(s)

ASPECT-Enterprise Linux 0 <= 3.08.03

MATRIX Series Linux 0 <= 3.08.03

NEXUS Series Linux 0 <= 3.08.03

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB acknowledges Gjoko Krstikj, Zero Science Lab, for reporting the potential vulnerabilities in responsible disclosure
.