cbcvebase.
CVE-2024-4007
published 2024-07-01

CVE-2024-4007: Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

high8.7CVSS 4.0
AVAACLATNPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSNAUNRUVDRELURed
EXPLOIT
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

Affected

15 ranges
VendorProductVersion rangeFixed in
abbaspect-ent-12_firmware< 3.07.023.07.02
abbaspect-ent-256_firmware< 3.07.023.07.02
abbaspect-ent-2_firmware< 3.07.023.07.02
abbaspect-ent-96_firmware< 3.07.023.07.02
abbaspect_enterprise
abbmatrix-11_firmware< 3.07.023.07.02
abbmatrix-216_firmware< 3.07.023.07.02
abbmatrix-232_firmware< 3.07.023.07.02
abbmatrix-264_firmware< 3.07.023.07.02
abbmatrix-296_firmware< 3.07.023.07.02
abbmatrix_series
abbnexus-2128_firmware< 3.07.023.07.02
abbnexus-264_firmware< 3.07.023.07.02
abbnexus-3-2128_firmware< 3.07.023.07.02
abbnexus-3-264_firmware< 3.07.023.07.02