Описание
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.
Уязвимые конфигурации
Конфигурация 1Версия до 002.006.000 (исключая)
Одновременно
cpe:2.3:o:schneider-electric:ecostruxure_panel_server_pas400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ecostruxure_panel_server_pas400:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 002.006.000 (исключая)
Одновременно
cpe:2.3:o:schneider-electric:ecostruxure_panel_server_pas600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ecostruxure_panel_server_pas600:-:*:*:*:*:*:*:*
Конфигурация 3Версия до 002.006.000 (исключая)
Одновременно
cpe:2.3:o:schneider-electric:ecostruxure_panel_server_pas600v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ecostruxure_panel_server_pas600v2:-:*:*:*:*:*:*:*
Конфигурация 4Версия до 002.006.000 (исключая)
Одновременно
cpe:2.3:o:schneider-electric:ecostruxure_panel_server_pas800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ecostruxure_panel_server_pas800:-:*:*:*:*:*:*:*
Конфигурация 5Версия до 002.006.000 (исключая)
Одновременно
cpe:2.3:o:schneider-electric:ecostruxure_panel_server_pas800v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ecostruxure_panel_server_pas800v2:-:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00291
Низкий
7.5 High
CVSS3
Дефекты
CWE-1188
Связанные уязвимости
CVSS3: 7.5
github
3 месяца назад
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.
EPSS
Процентиль: 21%
0.00291
Низкий
7.5 High
CVSS3
Дефекты
CWE-1188