CVE-2014-6617

Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:industrial.softing:fg-100_pb_profibus_firmware:fg-x00-pb_v2.02.0.00:*:*:*:*:*:*:*
cpe:2.3:h:industrial.softing:fg-100_pb_profibus:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:14

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/128976/Softing-FG-100-PB-Hardcoded-Backdoor.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/128976/Softing-FG-100-PB-Hardcoded-Backdoor.html - Exploit, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/533902/100/0/threaded - () http://www.securityfocus.com/archive/1/533902/100/0/threaded -
References () http://www.securityfocus.com/bid/70927 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/70927 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/98512 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/98512 - Third Party Advisory, VDB Entry
References () https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2014-005_softring_backdoor_account.txt - Exploit, Third Party Advisory () https://www.compass-security.com/fileadmin/Datein/Research/Advisories/CSNC-2014-005_softring_backdoor_account.txt - Exploit, Third Party Advisory

Information

Published : 2018-03-09 20:29

Updated : 2024-11-21 02:14


NVD link : CVE-2014-6617

Mitre link : CVE-2014-6617

CVE.ORG link : CVE-2014-6617


JSON object : View

Products Affected

industrial.softing

  • fg-100_pb_profibus_firmware
  • fg-100_pb_profibus
CWE
CWE-798

Use of Hard-coded Credentials