Back to overview

CVE-2024-51555

CRITICAL
10.0
CVSS 3.1
Description
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

Metadata

CVE ID
CVE-2024-51555
State
PUBLISHED
Assigner
ABB
Reserved
2024-10-29 11:48 UTC
Published
2024-12-05 12:59 UTC
Last updated
2025-08-28 14:38 UTC
Primary CWE
CWE-1393
CWE-1393 Use of Default Password
Vendor / Product
ABB / ASPECT-Enterprise
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (3)
VendorProductPlatformVersions
ABB ASPECT-Enterprise Linux 0 ≤ 3.07.02
ABB MATRIX Series Linux 0 ≤ 3.07.02
ABB NEXUS Series Linux 0 ≤ 3.07.02
Weakness (CWE)
CWESourceDescription
CWE-1393 cna CWE-1393 Use of Default Password
CVSS scores (2)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Back to overview