QID 590885
Date Published: 2022-06-30
QID 590885: Schneider Electric ETG3000 FactoryCast HMI Gateway Vulnerability (SEVD-2015-008-01)
The products affected
TSXETG3000 all versions
TSXETG3010 all versions
TSXETG3021 all versions
TSXETG3022 all versions
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Unauthenticated access to configuration data using XMLRPC interface. XMLRPC interface of device allows unauthenticated access to device configuration. Unauthenticated access to JAR file. It is possible to access rde.jar file without any authentication. Device is accessible over FTP using hard-coded credentials.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2015-008-01 for affected packages and patching details.
Vendor References
- SEVD-2015-008-01 -
www.se.com/in/en/download/document/SEVD-2015-008-01/
CVEs related to QID 590885
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2015-008-01 |
|