CVE-2014-9197: Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical Function
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9197?
CVE-2014-9197 has a medium severity level due to its potential to expose sensitive information.
How do I fix CVE-2014-9197?
To fix CVE-2014-9197, upgrade the firmware of the Schneider Electric ETG3000 FactoryCast HMI Gateway to version 1.60 IR 04 or later.
What type of information is exposed by CVE-2014-9197?
CVE-2014-9197 allows remote attackers to obtain sensitive setup and configuration information.
Which products are affected by CVE-2014-9197?
CVE-2014-9197 affects Schneider Electric's ETG3000 FactoryCast HMI Gateway with firmware versions before 1.60 IR 04.
Is CVE-2014-9197 a remote vulnerability?
Yes, CVE-2014-9197 is a remote vulnerability that can be exploited without physical access to the device.