Lucene search

K
cve[email protected]CVE-2013-2762
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2013-2762

2022-10-0316:15:01
CWE-352
CWE-255
web.nvd.nist.gov
23
schneider electric
magelis xbt
hmi controller
default password
authentication
configuration uploads
remote attackers
access restrictions
crafted configuration data.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.3%

The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.

Affected configurations

NVD
Node
schneider-electricmagelis_xbt_hmiMatch-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.3%

Related for CVE-2013-2762