Back to overview

CVE-2014-9197

10.0
CVSS 2.0
Description
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

Metadata

CVE ID
CVE-2014-9197
State
PUBLISHED
Assigner
icscert
Reserved
2014-12-02 00:00 UTC
Published
2015-01-27 11:00 UTC
Last updated
2025-09-05 21:19 UTC
Primary CWE
CWE-306
CWE-306
Vendor / Product
Schneider Electric / ETG3000 FactoryCast HMI Gateway
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 N/D CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products (1)
VendorProductPlatformVersions
Schneider Electric ETG3000 FactoryCast HMI Gateway TSXETG3000, TSXETG3010, TSXETG3021, TSXETG3022
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 N/D 2.0 cna AV:N/AC:L/Au:N/C:C/I:C/A:C
Back to overview