An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-036-05 | Mitigation Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-02-12 10:29
Updated : 2020-10-05 13:04
NVD link : CVE-2019-6549
Mitre link : CVE-2019-6549
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
kunbus
- pr100088_modbus_gateway_firmware
- pr100088_modbus_gateway