CVE-2014-9198
N/A
N/A
Summary
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Schneider Electric | ETG3000 FactoryCast HMI Gateway | TSXETG3000 | affected |
| Schneider Electric | ETG3000 FactoryCast HMI Gateway | TSXETG3010 | affected |
| Schneider Electric | ETG3000 FactoryCast HMI Gateway | TSXETG3021 | affected |
| Schneider Electric | ETG3000 FactoryCast HMI Gateway | TSXETG3022 | affected |
Weaknesses
- CWE-798: CWE-798
Workarounds
Schneider Electric recommends the FTP server be deactivated when not needed. The firmware update does not remove the hard-coded credentials.
Narendra Shinde also found that configuration files were accessible using default credentials. Schneider Electric recommends users change the default login credentials. This will protect configuration files from unauthorized access.
ADP Enrichment
CVE Program Container
Additional References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-020-02
- http://www.securityfocus.com/bid/72258
- http://www.securityfocus.com/bid/77765
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.