ZeroHour

CVE-2019-6859

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
Description

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

Vendors
schneider-electric
Products
bmx p34x firmware, bmx noe 0100 firmware, bmx noe 0110 firmware, bmx noc 0401 firmware, tsx p57x firmware, tsx ety x103 firmware, 140 cpu6x firmware, 140 noe 771x1 firmware, 140 noc 78x00 firmware, 140 noc 77101 firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.