CVE-2024-51555: Force Change of Default Credentials

9.3 CVSS

Description

Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials. 
Affected products:

ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02

Classification

CVE ID: CVE-2024-51555

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.3

Affected Products

Vendor: ABB

Product: ASPECT-Enterprise

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://search.abb.com/library/Download.aspx?DocumentID=9AKK108469A7497&LanguageCode=en&DocumentPartId=&Action=Launch

Timeline