Lucene search

K
cve[email protected]CVE-2014-9197
HistoryJan 27, 2015 - 7:59 p.m.

CVE-2014-9197

2015-01-2719:59:00
CWE-284
web.nvd.nist.gov
25
cve-2014-9197
schneider electric
etg3000
factorycast
hmi gateway
firmware
access control
sensitive information
remote attackers

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.4%

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

Affected configurations

NVD
Node
schneider-electricetg3000_factorycast_hmi_gateway_firmwareMatch1.60.2
AND
schneider-electrictsxetg3000Match-
OR
schneider-electrictsxetg3010Match-
OR
schneider-electrictsxetg3021Match-
OR
schneider-electrictsxetg3022Match-

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6.5 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.4%

Related for CVE-2014-9197