{"api_version":"1","generated_at":"2026-07-23T10:14:04+00:00","cve":"CVE-2014-9197","urls":{"html":"https://cve.report/CVE-2014-9197","api":"https://cve.report/api/cve/CVE-2014-9197.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-9197","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-9197"},"summary":{"title":"Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical Function","description":"The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.","state":"PUBLISHED","assigner":"icscert","published_at":"2015-01-27 19:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-306","CWE-284","CWE-306 CWE-306"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":10,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","version":"2.0"}}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-020-02","name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-020-02","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"Schneider Electric ETG3000 FactoryCast HMI Gateway Vulnerabilities | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-15-020-02","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-15-020-02","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-9197","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9197","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Schneider Electric","product":"ETG3000 FactoryCast HMI Gateway","version":"affected TSXETG3000","platforms":[]},{"source":"CNA","vendor":"Schneider Electric","product":"ETG3000 FactoryCast HMI Gateway","version":"affected TSXETG3010","platforms":[]},{"source":"CNA","vendor":"Schneider Electric","product":"ETG3000 FactoryCast HMI Gateway","version":"affected TSXETG3021","platforms":[]},{"source":"CNA","vendor":"Schneider Electric","product":"ETG3000 FactoryCast HMI Gateway","version":"affected TSXETG3022","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Schneider Electric has produced an updated firmware, labelled V1.60 \nIR 04. This firmware release moves the jar files directory in a secure \narea. The new firmware also includes the ability to disable the FTP \nserver. This updated firmware can be downloaded at:\n\n\n http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/?showAsIframe... http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Schneider Electric recommends the FTP server be deactivated when not \nneeded. The firmware update does not remove the hard-coded credentials.\n\n\nNarendra Shinde also found that configuration files were accessible \nusing default credentials. Schneider Electric recommends users change \nthe default login credentials. This will protect configuration files \nfrom unauthorized access.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Narendra Shinde of Qualys Security","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"9197","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"schneider-electric","cpe5":"etg3000_factorycast_hmi_gateway_firmware","cpe6":"1.60.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9197","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"tsxetg3000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9197","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"tsxetg3010","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9197","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"tsxetg3021","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9197","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"tsxetg3022","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2014-9197","qid":"590491","title":"Schneider Electric ETG3000 FactoryCast HMI Gateway Multiple Vulnerabilities (ICSA-15-020-02)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:40:24.525Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-020-02"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"ETG3000 FactoryCast HMI Gateway","vendor":"Schneider Electric","versions":[{"status":"affected","version":"TSXETG3000"},{"status":"affected","version":"TSXETG3010"},{"status":"affected","version":"TSXETG3021"},{"status":"affected","version":"TSXETG3022"}]}],"credits":[{"lang":"en","type":"finder","value":"Narendra Shinde of Qualys Security"}],"datePublic":"2015-01-20T07:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>\n\nThe Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.\n\n</p>"}],"value":"The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request."}],"metrics":[{"cvssV2_0":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":10,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-09-05T21:19:01.472Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-15-020-02"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Schneider Electric has produced an updated firmware, labelled V1.60 \nIR 04. This firmware release moves the jar files directory in a secure \narea. The new firmware also includes the ability to disable the FTP \nserver. This updated firmware can be downloaded at:</p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/?showAsIframe=true&amp;reference=ETG30xxV160-IR04\">http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/?showAsIframe...</a></p>\n\n<br>"}],"value":"Schneider Electric has produced an updated firmware, labelled V1.60 \nIR 04. This firmware release moves the jar files directory in a secure \narea. The new firmware also includes the ability to disable the FTP \nserver. This updated firmware can be downloaded at:\n\n\n http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/?showAsIframe... http://www.schneider-electric.com/download/WW/EN/details/681790255-TSXETG30xx-V160-IR4/"}],"source":{"advisory":"ICSA-15-020-02","discovery":"EXTERNAL"},"title":"Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical Function","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Schneider Electric recommends the FTP server be deactivated when not \nneeded. The firmware update does not remove the hard-coded credentials.</p>\n<p>Narendra Shinde also found that configuration files were accessible \nusing default credentials. Schneider Electric recommends users change \nthe default login credentials. This will protect configuration files \nfrom unauthorized access.</p>\n\n<br>"}],"value":"Schneider Electric recommends the FTP server be deactivated when not \nneeded. The firmware update does not remove the hard-coded credentials.\n\n\nNarendra Shinde also found that configuration files were accessible \nusing default credentials. Schneider Electric recommends users change \nthe default login credentials. This will protect configuration files \nfrom unauthorized access."}],"x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-9197","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-020-02","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-020-02"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-9197","datePublished":"2015-01-27T11:00:00.000Z","dateReserved":"2014-12-02T00:00:00.000Z","dateUpdated":"2025-09-05T21:19:01.472Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-01-27 19:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-306","CWE-284","CWE-306 CWE-306"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:schneider-electric:etg3000_factorycast_hmi_gateway_firmware:1.60.2:*:*:*:*:*:*:*","matchCriteriaId":"88278ADF-FD66-4110-80F2-059D98B5D740"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:tsxetg3000:-:*:*:*:*:*:*:*","matchCriteriaId":"46D2618A-486E-4055-BAFD-81F82C6B3D2A"},{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:tsxetg3010:-:*:*:*:*:*:*:*","matchCriteriaId":"55B765EF-1FA4-4994-AE8C-E11BF4F9B95E"},{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:tsxetg3021:-:*:*:*:*:*:*:*","matchCriteriaId":"EB5F2A27-898A-4F8F-BAD5-FA64370A6B98"},{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:tsxetg3022:-:*:*:*:*:*:*:*","matchCriteriaId":"2D483984-53F3-4972-9F6D-9446C06891D5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"9197","Ordinal":"1","Title":"Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authe","CVE":"CVE-2014-9197","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"9197","Ordinal":"1","NoteData":"The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.","Type":"Description","Title":"Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authe"},{"CveYear":"2014","CveId":"9197","Ordinal":"2","NoteData":"2015-01-27","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"9197","Ordinal":"3","NoteData":"2015-01-27","Type":"Other","Title":"Modified"}]}}}