Explore Vulnerabilities SQL Injection Cross-Site Scripting (XSS) Buffer Overflow Denial of Service Remote Code Execution Remote File Include Directory Traversal HTML Injection Stack Overflow Authentication Bypass
by: Gjoko 'LiquidWorm' Krstic vendor: ABB Ltd. Show More ABB Cylon Aspect 3.07.01 – Hard-coded Default Credentials The ABB BMS/BAS controller in ABB Cylon Aspect 3.07.01 operates with default and hard-coded credentials included in the installation package, making it vulnerable when exposed to the Internet. 6.1 CVSS HIGH Hard-coded Default Credentials 798 CWE Product Name ABB Cylon Aspect Platforms Tested GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, phpMyAdmin Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware: <=3.07.01 To: 2024