A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
140 Cpu6x Subscribe
140 Cpu6x Firmware Subscribe
140 Noc 77101 Subscribe
140 Noc 77101 Firmware Subscribe
140 Noc 78x00 Subscribe
140 Noc 78x00 Firmware Subscribe
140 Noe 771x1 Subscribe
140 Noe 771x1 Firmware Subscribe
Bmx Noc 0401 Subscribe
Bmx Noc 0401 Firmware Subscribe
Bmx Noe 0100 Subscribe
Bmx Noe 0100 Firmware Subscribe
Bmx Noe 0110 Subscribe
Bmx Noe 0110 Firmware Subscribe
Bmx P34x Subscribe
Bmx P34x Firmware Subscribe
Tsx Ety X103 Subscribe
Tsx Ety X103 Firmware Subscribe
Tsx P57x Subscribe
Tsx P57x Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-16406 A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T20:31:04.426Z

Reserved: 2019-01-25T00:00:00

Link: CVE-2019-6852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-20T22:15:12.030

Modified: 2024-11-21T04:47:16.920

Link: CVE-2019-6852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses