{"id": "CVE-2024-4007", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "cybersecurity@ch.abb.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.8, "attackVector": "ADJACENT_NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}], "cvssMetricV40": [{"type": "Secondary", "source": "cybersecurity@ch.abb.com", "cvssData": {"Safety": "NEGLIGIBLE", "version": "4.0", "Recovery": "USER", "baseScore": 8.7, "Automatable": "NO", "attackVector": "ADJACENT", "baseSeverity": "HIGH", "valueDensity": "DIFFUSE", "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Red", "exploitMaturity": "NOT_DEFINED", "providerUrgency": "RED", "userInteraction": "NONE", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "subIntegrityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "integrityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "availabilityRequirement": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "subConfidentialityImpact": "NONE", "vulnConfidentialityImpact": "HIGH", "confidentialityRequirement": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "vulnerabilityResponseEffort": "LOW", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED"}}]}, "published": "2024-07-01T13:15:06.077", "references": [{"url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A6101&LanguageCode=en&DocumentPartId=&Action=Launch", "tags": ["Vendor Advisory"], "source": "cybersecurity@ch.abb.com"}, {"url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A6101&LanguageCode=en&DocumentPartId=&Action=Launch", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Secondary", "source": "cybersecurity@ch.abb.com", "description": [{"lang": "en", "value": "CWE-1392"}]}], "descriptions": [{"lang": "en", "value": "Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured."}, {"lang": "es", "value": "Credencial predeterminada en el paquete de instalaci\u00f3n en ABB ASPECT; NEXUS Series; MATRIX Series versi\u00f3n 3.07 permite a un atacante iniciar sesi\u00f3n en instancias de productos mal configuradas."}], "lastModified": "2025-12-19T16:04:35.630", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:aspect-ent-12_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7160A7B-C86C-4B6F-9676-E609045DEB95", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:aspect-ent-12:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7D3FE8A0-B7B1-496F-918B-83AECEC80486"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:aspect-ent-2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33FFD0D5-84E8-4565-8CCC-41EBD13C3B33", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:aspect-ent-2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4C6351DE-8170-4023-B815-536030F9236E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:aspect-ent-256_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55BD3450-6363-493A-B927-D0B799B2E5A5", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:aspect-ent-256:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "125AAF0E-3CB2-4F5A-BA04-742918422422"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:aspect-ent-96_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D11512D2-4258-4187-B932-F0F2087B2655", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:aspect-ent-96:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9CC1901E-7476-4070-B649-E2EAE52A38A6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:matrix-11_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2500228A-DCF9-4D53-860D-33F8E3A7FE39", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:matrix-11:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7CC44F95-4AE8-48B3-AC2C-6A4EB20F62DD"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:matrix-216_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "07E65B3D-584F-4ECA-8C02-2B6BD776BA64", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:matrix-216:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "653A6815-9BC7-4BD4-BB67-DBCC666ED860"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:matrix-232_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B743E53A-C6B6-4458-A407-6C182E72147B", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:matrix-232:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "40C07D72-CA89-40A1-8EE8-F48A06DB7992"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:matrix-264_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A7F70B4-F8D7-445A-9DD6-82D0F4F146FB", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:matrix-264:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "80E8A1A8-8476-4C36-A6F6-258C2DC60388"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:matrix-296_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35AFA173-993C-4554-AE45-5978B047AE07", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:matrix-296:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "699E0759-590A-4362-9B5B-F876C1A020D1"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:nexus-2128_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8EC23B51-E42E-47E4-9419-7C18DA2E568E", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:nexus-2128:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "697D73AC-8567-4D25-B42F-FB584DAFF05F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:nexus-264_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EF3AC84-A778-4C20-BC7B-33E1338B9EAD", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:nexus-264:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "979B2BF4-885C-46B4-9093-E7CC35EBB397"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:nexus-3-2128_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CDA2D7A-A68A-4495-B522-108105980AA4", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:nexus-3-2128:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "66A14E33-5416-45D9-BBE4-61EFEC246E20"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:abb:nexus-3-264_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB976E8E-A73C-4BC0-84C1-9ED555865C15", "versionEndExcluding": "3.07.02"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:abb:nexus-3-264:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "96BF51C6-E220-4347-9505-48DAE2BB26B7"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cybersecurity@ch.abb.com"}