vendor:
ABB Cylon Aspect
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Hard-coded Default Credentials
798
CWE
Product Name: ABB Cylon Aspect
Affected Version From: NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware: <=3.07.01
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2024-4007
CPE:
Platforms Tested: GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, phpMyAdmin
2024
ABB Cylon Aspect 3.07.01 – Hard-coded Default Credentials
The ABB BMS/BAS controller in ABB Cylon Aspect 3.07.01 operates with default and hard-coded credentials included in the installation package, making it vulnerable when exposed to the Internet.
Mitigation:
To mitigate this vulnerability, users should change the default credentials to strong, unique passwords immediately after installation.