XML File Credentials Exposure on PR100088 Modbus Gateway by Industrial Control Systems Vendor
CVE-2019-6549

7.2HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
5 February 2019

What is CVE-2019-6549?

The vulnerability allows attackers to access plain-text credentials that are stored in an XML file on the PR100088 Modbus gateway. This can be exploited through unauthorized FTP access, leading to potential unauthorized control or manipulation of connected systems. Organizations should address this flaw by ensuring the security of their FTP services and applying relevant patches in order to safeguard sensitive credential data.

Affected Version(s)

PR100088 Modbus gateway All versions prior to Release R02 (or Software Version 1.1.13166)

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.