CVE-2014-6617: Critical severity softing fg-100 profibus vulnerability
Softing FG-100 PB PROFIBUS firmware version FG-x00-PBV2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6617?
CVE-2014-6617 has a high severity rating due to the presence of a hardcoded password that allows remote attackers to gain administrative access.
How do I fix CVE-2014-6617?
To mitigate CVE-2014-6617, it is recommended to update the firmware to a version that removes the hardcoded password.
What type of access can be gained through CVE-2014-6617?
CVE-2014-6617 allows attackers to obtain administrative access to the device via a TELNET session.
Which devices are affected by CVE-2014-6617?
CVE-2014-6617 affects the Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00.
Is the hardcoded password in CVE-2014-6617 user configurable?
No, the hardcoded password in CVE-2014-6617 is not user configurable, making it a significant security risk.