CVE-2014-9198: Schneider Electric ETG3000 FactoryCast HMI Gateway Use of Hard-coded Credentials
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9198?
CVE-2014-9198 has a medium severity level due to the presence of hardcoded credentials that can be exploited by remote attackers.
How do I fix CVE-2014-9198?
To fix CVE-2014-9198, update the ETG3000 FactoryCast HMI Gateway firmware to a version after 1.60 IR 04 that corrects the hardcoded credential issue.
What systems are affected by CVE-2014-9198?
CVE-2014-9198 affects Schneider Electric ETG3000 FactoryCast HMI Gateways with firmware versions up to and including 1.60 IR 04.
What type of attack is possible with CVE-2014-9198?
CVE-2014-9198 allows remote attackers to gain unauthorized access via FTP sessions due to hardcoded credentials.
Are there any workarounds for CVE-2014-9198?
Currently, there are no effective workarounds for CVE-2014-9198 besides upgrading the firmware to prevent unauthorized FTP access.