VulnerabilityModified
CVE-2014-9198
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
HIGH 10.0EPSS 4.19%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.19% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798, CWE-255
- Affected
- schneider-electric/etg3000 factorycast hmi gateway firmware · schneider-electric/tsxetg3000 · schneider-electric/tsxetg3010 · schneider-electric/tsxetg3021 · schneider-electric/tsxetg3022
- Source
- ics-cert@hq.dhs.gov
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.