10
CVSSv2

CVE-2011-4860

Published: 17/12/2011 Updated: 19/12/2011
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote malicious users to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric quantum ethernet module 140noe77100

schneider-electric quantum ethernet module 140noe77101

schneider-electric quantum ethernet module 140noe77111