CVE-2024-4007

EUVD-2024-32573
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
abbaspect-ent-12_firmware
𝑥
< 3.07.02
abbaspect-ent-2_firmware
𝑥
< 3.07.02
abbaspect-ent-256_firmware
𝑥
< 3.07.02
abbaspect-ent-96_firmware
𝑥
< 3.07.02
abbmatrix-11_firmware
𝑥
< 3.07.02
abbmatrix-216_firmware
𝑥
< 3.07.02
abbmatrix-232_firmware
𝑥
< 3.07.02
abbmatrix-264_firmware
𝑥
< 3.07.02
abbmatrix-296_firmware
𝑥
< 3.07.02
abbnexus-2128_firmware
𝑥
< 3.07.02
abbnexus-264_firmware
𝑥
< 3.07.02
abbnexus-3-2128_firmware
𝑥
< 3.07.02
abbnexus-3-264_firmware
𝑥
< 3.07.02
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
abbaspect-ent-2_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbaspect-ent-96_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-2128-a_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-2128-f_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-2128_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-2128-g_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-264-a_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-264-f_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-264_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-264-g_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-3-2128_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbnexus-3-264_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbmatrix-11_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbmatrix-216_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbmatrix-232_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbmatrix-264_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbaspect-ent-12_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbaspect-ent-256_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP
abbmatrix-296_firmware
3.0.0 ≤
𝑥
< 3.07.02
ADP