漏洞标题
N/A
漏洞描述信息
Schneider Electric 瑞想量子以太网模块,用于量子140NOE771* 和 140CPU65* 模块, Premium TSXETY* 和 TSXP57* 模块, M340 BMXNOE01* 和 BMXP3420* 模块, STB DIO STBNIC2212 和 STBNIP2* 模块,使得它们使用固定的密码对(1) AUTCSE,(2) AUT_CSE,(3) drusers,(4) ftpuser,(5) loader,(6) nic2212,(7) nimrohs2212,(8) nip2212,(9) noe77111_v500,(10) ntpupdate,(11) pcfactory,(12) sysdiag,(13) target,(14) test,(15) USER,(16) webserver accounts 进行访问,这使远程攻击者更容易通过(a) telnet,(b) Windriver Debug,或(c) FTP 端口获取访问权限。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Schneider Electric Quantum Ethernet模块安全漏洞
漏洞描述信息
Schneider Electric Quantum Ethernet模块对(1) AUTCSE(2) AUT_CSE(3)fdrusers(4)ftpuser(5)loader(6)nic2212(7)nimrohs2212(8) nip2212(9)noe77111_v500(10) ntpupdate(11) pcfactory(12) sysdiag(13) target(14) test(15) USER和(16) webserver accounts使用了硬码方式输入密码,使得远程攻击者可借助
CVSS信息
N/A
漏洞类别
授权问题