SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-8329

Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for…

HIGH 10.0EPSS 2.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
2.09% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
schrack/technik microcontrol firmware · schrack/technik microcontrol
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.