Default Credentials Vulnerability Affects ABB ASPECT Linux Products
CVE-2024-51554
9.8CRITICAL
What is CVE-2024-51554?
Recent findings highlight a serious security issue in ABB's ASPECT and NEXUS Series products running on Linux. The vulnerability arises from the presence of default credentials, which can be exploited by unauthorized individuals to gain access to the systems. This issue affects specific versions, including ABB ASPECT - Enterprise v3.08.02 and the NEXUS and MATRIX Series both at version 3.08.02. Organizations using these products are strongly encouraged to review their security configurations and take measures to remediate unauthorized access risks associated with default credentials.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.08.02
MATRIX Series Linux 0 <= 3.08.02
NEXUS Series Linux 0 <= 3.08.02
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure