First published: Tue Jan 27 2015(Updated: )
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
ETG3000 FactoryCast HMI Gateway Firmware | <=1.60.4 | |
Schneider-electric TSXETG3000 | ||
Schneider Electric TSXETG3010 | ||
Schneider Electric TSXETG3021 | ||
Schneider Electric TSXETG3022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9198 has a medium severity level due to the presence of hardcoded credentials that can be exploited by remote attackers.
To fix CVE-2014-9198, update the ETG3000 FactoryCast HMI Gateway firmware to a version after 1.60 IR 04 that corrects the hardcoded credential issue.
CVE-2014-9198 affects Schneider Electric ETG3000 FactoryCast HMI Gateways with firmware versions up to and including 1.60 IR 04.
CVE-2014-9198 allows remote attackers to gain unauthorized access via FTP sessions due to hardcoded credentials.
Currently, there are no effective workarounds for CVE-2014-9198 besides upgrading the firmware to prevent unauthorized FTP access.