PT-2015-2901 · Saia Burgess · Pcd7.D4Xxd+10

Artyom Kurbatov

·

Published

2015-12-23

·

Updated

2015-12-23

·

CVE-2015-7911

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Saia Burgess PCD1.M0xx0 versions prior to 1.24.50 Saia Burgess PCD1.M2xx0 versions prior to 1.24.50 Saia Burgess PCD2.M5xx0 versions prior to 1.24.50 Saia Burgess PCD3.Mxx60 versions prior to 1.24.50 Saia Burgess PCD3.Mxxx0 versions prior to 1.24.50 Saia Burgess PCD7.D4xxD versions prior to 1.24.50 Saia Burgess PCD7.D4xxV versions prior to 1.24.50 Saia Burgess PCD7.D4xxWTPF versions prior to 1.24.50 Saia Burgess PCD7.D4xxxT5F versions prior to 1.24.50 Saia Burgess PCD3.T665 versions prior to 1.24.41 Saia Burgess PCD3.T666 versions prior to 1.24.41
Description The issue is caused by hardcoded credentials in the software, allowing remote attackers to obtain administrative access via an FTP session. This can be exploited by attackers to gain unauthorized access to the system.
Recommendations For Saia Burgess PCD1.M0xx0 versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD1.M2xx0 versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD2.M5xx0 versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD3.Mxx60 versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD3.Mxxx0 versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD7.D4xxD versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD7.D4xxV versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD7.D4xxWTPF versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD7.D4xxxT5F versions prior to 1.24.50, update to version 1.24.50 or later. For Saia Burgess PCD3.T665 versions prior to 1.24.41, update to version 1.24.41 or later. For Saia Burgess PCD3.T666 versions prior to 1.24.41, update to version 1.24.41 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12268
CVE-2015-7911

Affected Products

Pcd1.M0Xx0
Pcd1.M2Xx0
Pcd2.M5Xx0
Pcd3.Mxx60
Pcd3.Mxxx0
Pcd3.T665
Pcd3.T666
Pcd7.D4Xxd
Pcd7.D4Xxv
Pcd7.D4Xxwtpf
Pcd7.D4Xxxt5F