Use of Hard-coded Credentials in ABB ASPECT-Enterprise, NEXUS Series, and MATRIX Series
CVE-2024-51547
9.3CRITICAL
What is CVE-2024-51547?
A significant security vulnerability exists in several ABB products including ASPECT-Enterprise, NEXUS Series, and MATRIX Series due to the use of hard-coded credentials. This issue can lead to unauthorized access, potentially compromising the integrity and confidentiality of sensitive data. Affected versions include ASPECT-Enterprise and both NEXUS and MATRIX Series up to version 3.08.03. It is crucial for users to update their systems to mitigate the risks associated with this vulnerability.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.08.03
MATRIX Series Linux 0 <= 3.08.03
NEXUS Series Linux 0 <= 3.08.03
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB acknowledges Gjoko Krstikj, Zero Science Lab, for reporting the potential vulnerabilities in responsible disclosure