#VU22882 Information disclosure in Schneider Electric products - CVE-2019-6852

 

#VU22882 Information disclosure in Schneider Electric products - CVE-2019-6852

Published: November 21, 2019


Vulnerability identifier: #VU22882
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-6852
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
M340 CPUs
M340 communication modules
Premium CPUs
Premium communication modules
Quantum CPUs
Quantum communication modules
Software vendor:
Schneider Electric

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the File Transfer Protocol (FTP) uses hardcoded credentials to automate the file transfer process. A remote attacker can use the Web server of the controller on an unsecure network and disclose the FTP hardcoded credentials.

This vulnerability affects the following products:

  • M340 CPUs:

BMX P34x

  • M340 communication modules:

BMX NOE 0100

BMX NOE 0110

BMX NOC 0401

  • Premium CPUs:
TSX P57x
  • Premium communication modules:
TSX ETY x103
  • Quantum CPUs:
140 CPU6x
  • Quantum communication modules:
140 NOE 771x1
140 NOC 78x00
140 NOC 77101

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.



External links