Vulnerability Description
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abb | Aspect-Ent-12 Firmware | < 3.07.02 |
| Abb | Aspect-Ent-12 | - |
| Abb | Aspect-Ent-2 Firmware | < 3.07.02 |
| Abb | Aspect-Ent-2 | - |
| Abb | Aspect-Ent-256 Firmware | < 3.07.02 |
| Abb | Aspect-Ent-256 | - |
| Abb | Aspect-Ent-96 Firmware | < 3.07.02 |
| Abb | Aspect-Ent-96 | - |
| Abb | Matrix-11 Firmware | < 3.07.02 |
| Abb | Matrix-11 | - |
| Abb | Matrix-216 Firmware | < 3.07.02 |
| Abb | Matrix-216 | - |
| Abb | Matrix-232 Firmware | < 3.07.02 |
| Abb | Matrix-232 | - |
| Abb | Matrix-264 Firmware | < 3.07.02 |
| Abb | Matrix-264 | - |
| Abb | Matrix-296 Firmware | < 3.07.02 |
| Abb | Matrix-296 | - |
| Abb | Nexus-2128 Firmware | < 3.07.02 |
| Abb | Nexus-2128 | - |
Related Weaknesses (CWE)
References
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A6101&LanguageVendor Advisory
- https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A6101&LanguageVendor Advisory
FAQ
What is CVE-2024-4007?
CVE-2024-4007 is a vulnerability with a CVSS score of 8.8 (HIGH). Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
How severe is CVE-2024-4007?
CVE-2024-4007 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4007?
Check the references section above for vendor advisories and patch information. Affected products include: Abb Aspect-Ent-12 Firmware, Abb Aspect-Ent-12, Abb Aspect-Ent-2 Firmware, Abb Aspect-Ent-2, Abb Aspect-Ent-256 Firmware.