CVE-2014-9198

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
27/01/2015
Last modified:
12/04/2025

Description

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:etg3000_factorycast_hmi_gateway_firmware:*:*:*:*:*:*:*:* 1.60.4 (including)
cpe:2.3:h:schneider-electric:tsxetg3000:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tsxetg3010:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tsxetg3021:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tsxetg3022:-:*:*:*:*:*:*:*