A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
140 Cpu6x
Subscribe
140 Cpu6x Firmware
Subscribe
140 Noc 77101
Subscribe
140 Noc 77101 Firmware
Subscribe
140 Noc 78x00
Subscribe
140 Noc 78x00 Firmware
Subscribe
140 Noe 771x1
Subscribe
140 Noe 771x1 Firmware
Subscribe
Bmx Noc 0401
Subscribe
Bmx Noc 0401 Firmware
Subscribe
Bmx Noe 0100
Subscribe
Bmx Noe 0100 Firmware
Subscribe
Bmx Noe 0110
Subscribe
Bmx Noe 0110 Firmware
Subscribe
Bmx P34x
Subscribe
Bmx P34x Firmware
Subscribe
Tsx Ety X103
Subscribe
Tsx Ety X103 Firmware
Subscribe
Tsx P57x
Subscribe
Tsx P57x Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-16406 | A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T20:31:04.426Z
Reserved: 2019-01-25T00:00:00
Link: CVE-2019-6852
No data.
Status : Modified
Published: 2019-11-20T22:15:12.030
Modified: 2024-11-21T04:47:16.920
Link: CVE-2019-6852
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD