PT-2015-4153 · Schneider Electric · Etg3000 Factorycast Hmi Gateway

Narendra Shinde

·

Published

2015-01-27

·

Updated

2025-09-05

·

CVE-2014-9198

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schneider Electric ETG3000 FactoryCast HMI Gateway versions through 1.60 IR 04
Description The issue concerns hardcoded credentials in the FTP server, making it easier for remote attackers to gain access via an FTP session.
Recommendations For versions through 1.60 IR 04, consider disabling the FTP server or restricting its access until a patch is available to remove the hardcoded credentials.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9198

Affected Products

Etg3000 Factorycast Hmi Gateway