CVE-2019-6549

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
12/02/2019
Last modified:
05/10/2020

Description

An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:kunbus:pr100088_modbus_gateway_firmware:*:*:*:*:*:*:*:* r02 (excluding)
cpe:2.3:h:kunbus:pr100088_modbus_gateway:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools