CVE-2013-2762
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.10% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255, CWE-352
- Affected
- schneider-electric/magelis xbt hmi
- Source
- cve@mitre.org
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdfUS Government Resource
- http://ics-cert.us-cert.gov/pdf/ICSA-13-077-01A.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.