A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default on device, it is not using a SSL in settings and if multiple request of the page "Access Control" (IP-address device/ups/pas_cont.htm) account data will be sent in cleartext
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
66074 Mge Network Management Card Transverse
Subscribe
Mge Comet Ups
Subscribe
Mge Eps 6000
Subscribe
Mge Eps 7000
Subscribe
Mge Eps 8000
Subscribe
Mge Galaxy 3000
Subscribe
Mge Galaxy 4000
Subscribe
Mge Galaxy 5000
Subscribe
Mge Galaxy 6000
Subscribe
Mge Galaxy 9000
Subscribe
Mge Galaxy Pw
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18985 | A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default on device, it is not using a SSL in settings and if multiple request of the page "Access Control" (IP-address device/ups/pas_cont.htm) account data will be sent in cleartext |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-05T06:24:11.827Z
Reserved: 2018-02-19T00:00:00
Link: CVE-2018-7246
No data.
Status : Modified
Published: 2018-04-18T20:29:00.577
Modified: 2024-11-21T04:11:52.270
Link: CVE-2018-7246
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD