CVE-2024-4007

HIGH
Published Jul 1, 2024 Modified Dec 19, 2025 CWE-1392

Description

Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

Is your site exposed to CVE-2024-4007?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.8
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-1392 CWE-1392

Affected Products

Vendor Product
abb aspect-ent-12_firmware
abb aspect-ent-12
abb aspect-ent-2_firmware
abb aspect-ent-2
abb aspect-ent-256_firmware
abb aspect-ent-256
abb aspect-ent-96_firmware
abb aspect-ent-96
abb matrix-11_firmware
abb matrix-11
abb matrix-216_firmware
abb matrix-216
abb matrix-232_firmware
abb matrix-232
abb matrix-264_firmware
abb matrix-264
abb matrix-296_firmware
abb matrix-296
abb nexus-2128_firmware
abb nexus-2128
abb nexus-264_firmware
abb nexus-264
abb nexus-3-2128_firmware
abb nexus-3-2128
abb nexus-3-264_firmware
abb nexus-3-264

References

Frequently Asked Questions

What is CVE-2024-4007? +
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. It has a CVSS v3.1 base score of 8.8 (HIGH).
How severe is CVE-2024-4007? +
CVE-2024-4007 has a CVSS v3.1 score of 8.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-4007? +
CVE-2024-4007 affects products from abb, specifically: aspect-ent-12, aspect-ent-12_firmware, aspect-ent-2, aspect-ent-256, aspect-ent-256_firmware, aspect-ent-2_firmware, aspect-ent-96, aspect-ent-96_firmware, matrix-11, matrix-11_firmware, matrix-216, matrix-216_firmware, matrix-232, matrix-232_firmware, matrix-264, matrix-264_firmware, matrix-296, matrix-296_firmware, nexus-2128, nexus-2128_firmware, nexus-264, nexus-264_firmware, nexus-3-2128, nexus-3-2128_firmware, nexus-3-264, nexus-3-264_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-4007? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-4007 — free, no signup required.