Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
ABB ASPECT firmware contains embedded (hardcoded) default login credentials (CWE-798) that are publicly available and known. The absence of a mechanism forcing the change of these credentials after first startup means that an attacker can use publicly available login/password combinations to authenticate to the system over the network. The vulnerability is also classified as CWE-1287 (improper validation of authentication data), which indicates a lack of appropriate security verification of credentials used.
An attacker without any permissions can remotely gain full access to the device — confidentiality, integrity and system availability are threatened. In industrial and building environments, this can lead to takeover of building management infrastructure (BMS) control.
Patches available from the manufacturer should be applied in accordance with references (ABB documentation with ID 9AKK108469A7497). Until the fix is implemented, it is recommended to immediately change default credentials to strong, unique passwords and restrict network access to ASPECT devices through firewall and network segmentation.
ABB ASPECT - Enterprise version 3.07.02, NEXUS Series version 3.07.02, MATRIX Series version 3.07.02
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAbb Aspect Ent 12
HWAbball versionsAbb Aspect Ent 12 Firmware
OSAbb≤ 3.07.02Abb Aspect Ent 2
HWAbball versionsAbb Aspect Ent 256
HWAbball versionsAbb Aspect Ent 256 Firmware
OSAbb≤ 3.07.02Abb Aspect Ent 2 Firmware
OSAbb≤ 3.07.02Abb Aspect Ent 96
HWAbball versionsAbb Aspect Ent 96 Firmware
OSAbb≤ 3.07.02Abb Matrix 11
HWAbball versionsAbb Matrix 11 Firmware
OSAbb≤ 3.07.02Abb Matrix 216
HWAbball versionsAbb Matrix 216 Firmware
OSAbb≤ 3.07.02Abb Matrix 232
HWAbball versionsAbb Matrix 232 Firmware
OSAbb≤ 3.07.02Abb Matrix 264
HWAbball versionsAbb Matrix 264 Firmware
OSAbb≤ 3.07.02Abb Matrix 296
HWAbball versionsAbb Matrix 296 Firmware
OSAbb≤ 3.07.02Abb Nexus 2128
HWAbball versionsAbb Nexus 2128 A
HWAbball versionsAbb Nexus 2128 A Firmware
OSAbb≤ 3.07.02Abb Nexus 2128 F
HWAbball versionsAbb Nexus 2128 F Firmware
OSAbb≤ 3.07.02Abb Nexus 2128 Firmware
OSAbb≤ 3.07.02Abb Nexus 2128 G
HWAbball versionsAbb Nexus 2128 G Firmware
OSAbb≤ 3.07.02Abb Nexus 264
HWAbball versionsAbb Nexus 264 A
HWAbball versionsAbb Nexus 264 A Firmware
OSAbb≤ 3.07.02Abb Nexus 264 F
HWAbball versions
Related vulnerabilities
Zakodowane na stałe dane uwierzytelniające w urządzeniach ABB ASPECT/NEXUS/MATRIX
Słabe reguły resetowania hasła w urządzeniach ABB ASPECT i NEXUS/MATRIX
Session Fixation w ABB ASPECT i NEXUS/MATRIX Series — przejęcie sesji użytkownika
RCE poprzez nieprawidłową walidację danych wejściowych w ABB ASPECT/NEXUS/MATRIX
RCE poprzez nieautoryzowany dostęp w urządzeniach ABB ASPECT/NEXUS/MATRIX