PT-2014-2002 · Softing · Softing Fg-100 Pb Profibus

Published

2014-09-15

·

Updated

2018-10-09

·

CVE-2014-6617

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Softing FG-100 PB PROFIBUS firmware version FG-x00-PB V2.02.0.00
Description The issue is related to a hardcoded password for the root account in the firmware, allowing remote attackers to gain administrative access via a TELNET session. This is due to the use of predefined credentials. An attacker can exploit this to obtain root access to the device using a Telnet connection.
Recommendations For Softing FG-100 PB PROFIBUS firmware version FG-x00-PB V2.02.0.00, consider changing the hardcoded password for the root account to a unique and secure password to prevent unauthorized access. As a temporary workaround, consider disabling TELNET access until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00700
CVE-2014-6617

Affected Products

Softing Fg-100 Pb Profibus