vendor:
                    ABB Cylon Aspect
                by:
                    Gjoko 'LiquidWorm' Krstic
                6.1
                        CVSS
                    HIGH
                    Hard-coded Default Credentials
                    798
                        CWE
                    Product Name: ABB Cylon Aspect
                    Affected Version From:  NEXUS Series, MATRIX-2 Series, ASPECT-Enterprise, ASPECT-Studio Firmware: <=3.07.01
                    Affected Version To:  
                    Patch Exists: NO
                    Related CWE: CVE-2024-4007
                    CPE:  
                    Platforms Tested:  GNU/Linux, Intel processors, PHP, AspectFT Automation Application Server, lighttpd, Apache, OpenJDK, phpMyAdmin
                    2024
                    ABB Cylon Aspect 3.07.01 – Hard-coded Default Credentials
The ABB BMS/BAS controller in ABB Cylon Aspect 3.07.01 operates with default and hard-coded credentials included in the installation package, making it vulnerable when exposed to the Internet.
Mitigation:
					To mitigate this vulnerability, users should change the default credentials to strong, unique passwords immediately after installation.