A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-281-02/ | not applicable vendor advisory |
https://www.se.com/ww/en/download/document/SEVD-2019-316-02%20/ | vendor advisory |