CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-51547

CVSS 9.3v4.0pub. 2025-02-06upd. 2025-05-23

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

🤖 AI Analysis
How it works

The manufacturer embedded hard-coded, immutable authentication data (login/password) in the device firmware, which are identical across all units of a given model. An attacker who obtains this data — for example, through firmware analysis or public disclosure — can authenticate to any vulnerable device over the network without any user interaction. Because the attack vector is network-based and the attack requires no privileges or special conditions, this vulnerability is particularly dangerous for devices accessible from the Internet or unprotected internal networks.

Impact

An attacker can gain full, unauthorized access to the device, which consequently leads to violations of confidentiality, integrity, and availability of building management systems or industrial infrastructure.

Mitigation & patch

Apply patches available from the manufacturer according to references (ABB public advisory number 9AKK108470A6775). Until the update is applied, it is recommended to isolate devices from public networks and restrict network access to these systems exclusively to trusted hosts using a firewall.

Who is affected

ABB ASPECT-Enterprise: versions up to 3.* inclusive; ABB NEXUS Series: versions up to 3.* inclusive; ABB MATRIX Series: versions up to 3.* inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Abb Aspect Ent 12

    HW
    Abb
    all versions
  • Abb Aspect Ent 12 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Aspect Ent 2

    HW
    Abb
    all versions
  • Abb Aspect Ent 256

    HW
    Abb
    all versions
  • Abb Aspect Ent 256 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Aspect Ent 2 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Aspect Ent 96

    HW
    Abb
    all versions
  • Abb Aspect Ent 96 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Matrix 11

    HW
    Abb
    all versions
  • Abb Matrix 11 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Matrix 216

    HW
    Abb
    all versions
  • Abb Matrix 216 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Matrix 232

    HW
    Abb
    all versions
  • Abb Matrix 232 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Matrix 264

    HW
    Abb
    all versions
  • Abb Matrix 264 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Matrix 296

    HW
    Abb
    all versions
  • Abb Matrix 296 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Nexus 2128

    HW
    Abb
    all versions
  • Abb Nexus 2128 A

    HW
    Abb
    all versions
  • Abb Nexus 2128 A Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Nexus 2128 F

    HW
    Abb
    all versions
  • Abb Nexus 2128 F Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Nexus 2128 Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Nexus 2128 G

    HW
    Abb
    all versions
  • Abb Nexus 2128 G Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Nexus 264

    HW
    Abb
    all versions
  • Abb Nexus 264 A

    HW
    Abb
    all versions
  • Abb Nexus 264 A Firmware

    OS
    Abb
    ≤ 3.08.03
  • Abb Nexus 264 F

    HW
    Abb
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-48840CRITICAL9.3PL ✓same product

RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX

CVE-2024-48845CRITICAL9.3PL ✓same product

Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX

CVE-2024-11317CRITICAL9.3PL ✓same product

Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika

CVE-2024-48839CRITICAL9.3PL ✓same product

RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX

CVE-2024-51545CRITICAL9.3PL ✓same product

Enumeracja nazw użytkowników w ABB ASPECT, NEXUS i MATRIX Series