Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32573 Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
Fixes

Solution

ABB Strongly recommends the following actions on any released SW version of ASPECT: - Change the PHPmyAdmin Password according to the system manual:  All customers who operate the ASPECT System with its default password are recommended to replace this default password with a unique, secure password, containing a mix of characters, numbers, and special characters with at least 10 characters in length. - Never expose open ports to the ASPECT product towards the Internet or any insecure network. - When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. - ABB recommends that customers shall apply the latest product update at the earliest convenience.


Workaround

ASPECT system shall not be connected directly to untrusted networks such as the Internet. If remote access to an ASPECT system is a customer requirement, the system shall operate behind a firewall. User accessing ASPECT remotely shall do this using a VPN Gateway allowing access to the particular network segment where ASPECT is installed and configured in. Note: it is crucial that the VPN Gateway and Network is setup in accordance with best industry standards and maintained in terms of security patches for all related components. Any default credentials shall be exchanged with a unique credential supporting adequate strength.

History

Fri, 19 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Abb
Abb aspect-ent-12
Abb aspect-ent-12 Firmware
Abb aspect-ent-2
Abb aspect-ent-256
Abb aspect-ent-256 Firmware
Abb aspect-ent-2 Firmware
Abb aspect-ent-96
Abb aspect-ent-96 Firmware
Abb matrix-11
Abb matrix-11 Firmware
Abb matrix-216
Abb matrix-216 Firmware
Abb matrix-232
Abb matrix-232 Firmware
Abb matrix-264
Abb matrix-264 Firmware
Abb matrix-296
Abb matrix-296 Firmware
Abb nexus-2128
Abb nexus-2128 Firmware
Abb nexus-264
Abb nexus-264 Firmware
Abb nexus-3-2128
Abb nexus-3-2128 Firmware
Abb nexus-3-264
Abb nexus-3-264 Firmware
CPEs cpe:2.3:h:abb:aspect-ent-12:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:aspect-ent-256:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:aspect-ent-2:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:aspect-ent-96:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:matrix-11:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:matrix-216:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:matrix-232:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:matrix-264:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:matrix-296:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:nexus-2128:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:nexus-264:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:nexus-3-2128:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:nexus-3-264:-:*:*:*:*:*:*:*
cpe:2.3:o:abb:aspect-ent-12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:aspect-ent-256_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:aspect-ent-2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:aspect-ent-96_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:matrix-11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:matrix-216_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:matrix-232_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:matrix-264_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:matrix-296_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:nexus-2128_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:nexus-264_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:nexus-3-2128_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:nexus-3-264_firmware:*:*:*:*:*:*:*:*
Vendors & Products Abb
Abb aspect-ent-12
Abb aspect-ent-12 Firmware
Abb aspect-ent-2
Abb aspect-ent-256
Abb aspect-ent-256 Firmware
Abb aspect-ent-2 Firmware
Abb aspect-ent-96
Abb aspect-ent-96 Firmware
Abb matrix-11
Abb matrix-11 Firmware
Abb matrix-216
Abb matrix-216 Firmware
Abb matrix-232
Abb matrix-232 Firmware
Abb matrix-264
Abb matrix-264 Firmware
Abb matrix-296
Abb matrix-296 Firmware
Abb nexus-2128
Abb nexus-2128 Firmware
Abb nexus-264
Abb nexus-264 Firmware
Abb nexus-3-2128
Abb nexus-3-2128 Firmware
Abb nexus-3-264
Abb nexus-3-264 Firmware

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2024-08-01T20:26:57.247Z

Reserved: 2024-04-19T17:08:37.839Z

Link: CVE-2024-4007

cve-icon Vulnrichment

Updated: 2024-08-01T20:26:57.247Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-01T13:15:06.077

Modified: 2025-12-19T16:04:35.630

Link: CVE-2024-4007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses