The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-9022 The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.
Fixes

Solution

Schneider Electric has produced an updated firmware, labelled V1.60 IR 04. This firmware release moves the jar files directory in a secure area. The new firmware also includes the ability to disable the FTP server. This updated firmware can be downloaded at: http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/?showAsIframe... http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/


Workaround

Schneider Electric recommends the FTP server be deactivated when not needed. The firmware update does not remove the hard-coded credentials. Narendra Shinde also found that configuration files were accessible using default credentials. Schneider Electric recommends users change the default login credentials. This will protect configuration files from unauthorized access.

History

Fri, 05 Sep 2025 21:30:00 +0000

Type Values Removed Values Added
Title Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV2_0

{'score': 7.8, 'vector': 'AV:N/AC:L/Au:N/C:C/I:N/A:N'}

cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-09-05T21:19:01.472Z

Reserved: 2014-12-02T00:00:00

Link: CVE-2014-9197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-01-27T19:59:00.040

Modified: 2025-09-05T22:15:33.210

Link: CVE-2014-9197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.