CVE-2024-4007
Hard coded default credential contained in install package
Severity Score
8.7
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
ABB Cylon Aspect version 3.07.01 BMS/BAS controller is operating with default and hard-coded credentials contained in install package while exposed to the Internet.
*Credits:
ABB likes to thank https://divd.nl for reporting the vulnerability in responsible disclosure.
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-04-19 CVE Reserved
- 2024-07-01 CVE Published
- 2024-07-02 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1392: Use of Default Credentials
CAPEC
- CAPEC-49: Password Brute Forcing
References (1)
URL | Tag | Source |
---|---|---|
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A6101&LanguageCode=en&DocumentPartId=&Action=Launch |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
ABB Search vendor "ABB" | ASPECT Enterprise (ASP-ENT-x) Search vendor "ABB" for product "ASPECT Enterprise (ASP-ENT-x)" | 3.07 Search vendor "ABB" for product "ASPECT Enterprise (ASP-ENT-x)" and version "3.07" | en |
Affected
| ||||||
ABB Search vendor "ABB" | NEXUS Series (NEX-2x, NEXUS-3-x) Search vendor "ABB" for product "NEXUS Series (NEX-2x, NEXUS-3-x)" | 3.07 Search vendor "ABB" for product "NEXUS Series (NEX-2x, NEXUS-3-x)" and version "3.07" | en |
Affected
| ||||||
ABB Search vendor "ABB" | MATRIX Series(MAT-x) Search vendor "ABB" for product "MATRIX Series(MAT-x)" | 3.07 Search vendor "ABB" for product "MATRIX Series(MAT-x)" and version "3.07" | en |
Affected
|