CRITICAL🇵🇱 Wersja polska

CVE-2024-51551

CVSS 9.3v4.0pub. 2024-12-05upd. 2025-02-27

Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

🤖 AI Analysis
How it works

ABB ASPECT firmware contains embedded (hardcoded) default login credentials (CWE-798) that are publicly available and known. The absence of a mechanism forcing the change of these credentials after first startup means that an attacker can use publicly available login/password combinations to authenticate to the system over the network. The vulnerability is also classified as CWE-1287 (improper validation of authentication data), which indicates a lack of appropriate security verification of credentials used.

Impact

An attacker without any permissions can remotely gain full access to the device — confidentiality, integrity and system availability are threatened. In industrial and building environments, this can lead to takeover of building management infrastructure (BMS) control.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with references (ABB documentation with ID 9AKK108469A7497). Until the fix is implemented, it is recommended to immediately change default credentials to strong, unique passwords and restrict network access to ASPECT devices through firewall and network segmentation.

Who is affected

ABB ASPECT - Enterprise version 3.07.02, NEXUS Series version 3.07.02, MATRIX Series version 3.07.02

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Abb Aspect Ent 12

    HW
    Abb
    all versions
  • Abb Aspect Ent 12 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Aspect Ent 2

    HW
    Abb
    all versions
  • Abb Aspect Ent 256

    HW
    Abb
    all versions
  • Abb Aspect Ent 256 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Aspect Ent 2 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Aspect Ent 96

    HW
    Abb
    all versions
  • Abb Aspect Ent 96 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Matrix 11

    HW
    Abb
    all versions
  • Abb Matrix 11 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Matrix 216

    HW
    Abb
    all versions
  • Abb Matrix 216 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Matrix 232

    HW
    Abb
    all versions
  • Abb Matrix 232 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Matrix 264

    HW
    Abb
    all versions
  • Abb Matrix 264 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Matrix 296

    HW
    Abb
    all versions
  • Abb Matrix 296 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Nexus 2128

    HW
    Abb
    all versions
  • Abb Nexus 2128 A

    HW
    Abb
    all versions
  • Abb Nexus 2128 A Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Nexus 2128 F

    HW
    Abb
    all versions
  • Abb Nexus 2128 F Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Nexus 2128 Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Nexus 2128 G

    HW
    Abb
    all versions
  • Abb Nexus 2128 G Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Nexus 264

    HW
    Abb
    all versions
  • Abb Nexus 264 A

    HW
    Abb
    all versions
  • Abb Nexus 264 A Firmware

    OS
    Abb
    ≤ 3.07.02
  • Abb Nexus 264 F

    HW
    Abb
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-51547CRITICAL9.3PL ✓same product

Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX

CVE-2024-48845CRITICAL9.3PL ✓same product

Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX

CVE-2024-11317CRITICAL9.3PL ✓same product

Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika

CVE-2024-48839CRITICAL9.3PL ✓same product

RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX

CVE-2024-48840CRITICAL9.3PL ✓same product

RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX