vendor:
FLXeon Series, CBX Series, CBT Series, CBV Series, ABB UC32 Series Main Plant Controllers
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Default Credentials
798
CWE
Product Name: FLXeon Series, CBX Series, CBT Series, CBV Series, ABB UC32 Series Main Plant Controllers
Affected Version From: FLXeon Series (FBXi Series, FBTi Series, FBVi Series), CBX Series (FLX Series), CBT Series, CBV Series, ABB UC32 Series Main Plant Controllers (Cylon's UnitronUC32.xx) with firmware <=9.3.4
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: h:abb:cylon_flxeon:9.3.4
Platforms Tested: Linux, NodeJS, Express
2024
ABB Cylon FLXeon 9.3.4 Default Credentials
The ABB Cylon FLXeon BACnet controller in versions <=9.3.4 uses weak default administrative credentials, which can be exploited in remote password attacks to gain unauthorized access and full control of the system.
Mitigation:
Change the default administrative credentials immediately after installation to strong, unique passwords to mitigate this vulnerability.