Default Credential Vulnerabilities Expose ABB Enterprise and NEXUS Series to Unauthorized Access

CVE-2024-51555
10CRITICAL

Key Information

Vendor
Abb
Status
Aspect-enterprise
Nexus Series
Matrix Series
Vendor
CVE Published:
5 December 2024

Summary

Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

Affected Version(s)

ASPECT-Enterprise <= 3.07.02

NEXUS Series <= 3.07.02

MATRIX Series <= 3.07.02

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Risk change from: null to: 10 - (CRITICAL)

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
.