First published: Fri Mar 09 2018(Updated: )
Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Softing FG-100 PROFIBUS | =fg-x00-pb_v2.02.0.00 | |
Softing FG-100 PROFIBUS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6617 has a high severity rating due to the presence of a hardcoded password that allows remote attackers to gain administrative access.
To mitigate CVE-2014-6617, it is recommended to update the firmware to a version that removes the hardcoded password.
CVE-2014-6617 allows attackers to obtain administrative access to the device via a TELNET session.
CVE-2014-6617 affects the Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00.
No, the hardcoded password in CVE-2014-6617 is not user configurable, making it a significant security risk.