CVE-2014-9197

Summary

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

Affected Software

VendorProductVersion RangeStatus
Schneider ElectricETG3000 FactoryCast HMI GatewayTSXETG3000affected
Schneider ElectricETG3000 FactoryCast HMI GatewayTSXETG3010affected
Schneider ElectricETG3000 FactoryCast HMI GatewayTSXETG3021affected
Schneider ElectricETG3000 FactoryCast HMI GatewayTSXETG3022affected

Weaknesses

  • CWE-306: CWE-306

Workarounds

Schneider Electric recommends the FTP server be deactivated when not needed. The firmware update does not remove the hard-coded credentials.

Narendra Shinde also found that configuration files were accessible using default credentials. Schneider Electric recommends users change the default login credentials. This will protect configuration files from unauthorized access.

ADP Enrichment

CVE Program Container

Additional References

References