The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
M340 Ethernet Module Bmxnoe0100
Subscribe
M340 Ethernet Module Bmxnoe0110
Subscribe
M340 Ethernet Module Bmxp342020
Subscribe
M340 Ethernet Module Bmxp342030
Subscribe
Premium Ethernet Module Tsxety4103
Subscribe
Premium Ethernet Module Tsxety5103
Subscribe
Premium Ethernet Module Tsxp57163m
Subscribe
Premium Ethernet Module Tsxp572634m
Subscribe
Premium Ethernet Module Tsxp573634m
Subscribe
Premium Ethernet Module Tsxp574634m
Subscribe
Premium Ethernet Module Tsxp575634m
Subscribe
Premium Ethernet Module Tsxp576634m
Subscribe
Quantum Ethernet Module 140cpu65150
Subscribe
Quantum Ethernet Module 140cpu65160
Subscribe
Quantum Ethernet Module 140cpu65260
Subscribe
Quantum Ethernet Module 140noe77100
Subscribe
Quantum Ethernet Module 140noe77101
Subscribe
Quantum Ethernet Module 140noe77111
Subscribe
Stb Dio Ethernet Module Stbnic2212
Subscribe
Stb Dio Ethernet Module Stbnip2212
Subscribe
Stb Dio Ethernet Module Stbnip2311
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-4776 | The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T00:16:35.051Z
Reserved: 2011-12-16T00:00:00
Link: CVE-2011-4859
No data.
Status : Deferred
Published: 2011-12-17T11:55:11.917
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-4859
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD