PT-2013-3915 · Schneider Electric · Magelis Xbt Hmi

Published

2013-04-04

·

Updated

2013-04-04

·

CVE-2013-2762

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schneider Electric Magelis XBT HMI controller (affected versions not specified)
Description The issue concerns a default password used for authentication of configuration uploads, making it easier for remote attackers to bypass intended access restrictions by using crafted configuration data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2762

Affected Products

Magelis Xbt Hmi