CVE-2014-9198
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://ics-cert.us-cert.gov/advisories/ICSA-15-020-02
References
CWEs
CWE-798 CWE-255
Verify integrity in audit chain (admin only). AS-IS.