PT-2014-2002 · Softing · Softing Fg-100 Pb Profibus
Published
2014-09-15
·
Updated
2018-10-09
·
CVE-2014-6617
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Softing FG-100 PB PROFIBUS firmware version FG-x00-PB V2.02.0.00
Description
The issue is related to a hardcoded password for the root account in the firmware, allowing remote attackers to gain administrative access via a TELNET session. This is due to the use of predefined credentials. An attacker can exploit this to obtain root access to the device using a Telnet connection.
Recommendations
For Softing FG-100 PB PROFIBUS firmware version FG-x00-PB V2.02.0.00, consider changing the hardcoded password for the root account to a unique and secure password to prevent unauthorized access. As a temporary workaround, consider disabling TELNET access until a patch is available. Restrict access to the device to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Softing Fg-100 Pb Profibus