Default Credentials Vulnerability Affects ABB ASPECT Linux Products
CVE-2024-51554

9.1CRITICAL

Key Information:

Vendor
Abb
Status
Aspect-enterprise
Nexus Series
Matrix Series
Vendor
CVE Published:
5 December 2024

Summary

Recent findings highlight a serious security issue in ABB's ASPECT and NEXUS Series products running on Linux. The vulnerability arises from the presence of default credentials, which can be exploited by unauthorized individuals to gain access to the systems. This issue affects specific versions, including ABB ASPECT - Enterprise v3.08.02 and the NEXUS and MATRIX Series both at version 3.08.02. Organizations using these products are strongly encouraged to review their security configurations and take measures to remediate unauthorized access risks associated with default credentials.

Affected Version(s)

ASPECT-Enterprise Linux 0 <= 3.08.02

MATRIX Series Linux 0 <= 3.08.02

NEXUS Series Linux 0 <= 3.08.02

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
.