CVE Feed

    Dashboard / CVE / CVE-2011-4859

    CVE-2011-4859

    The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.

    Published:Dec 17, 2011
    Last Modified:Apr 11, 2025
    EPS:Dec 17, 2011
    EPSS Score:0.07001
    CVSS Score:10

    Affected Products

    Vendor
    Schneider-electric
    Product
    M340 Ethernet Module Bmxnoe0100
    Vendor
    Schneider-electric
    Product
    M340 Ethernet Module Bmxnoe0110
    Vendor
    Schneider-electric
    Product
    M340 Ethernet Module Bmxp342020
    Vendor
    Schneider-electric
    Product
    M340 Ethernet Module Bmxp342030
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxety4103
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxety5103
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxp57163m
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxp572634m
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxp573634m
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxp574634m
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxp575634m
    Vendor
    Schneider-electric
    Product
    Premium Ethernet Module Tsxp576634m
    Vendor
    Schneider-electric
    Product
    Quantum Ethernet Module 140cpu65150
    Vendor
    Schneider-electric
    Product
    Quantum Ethernet Module 140cpu65160
    Vendor
    Schneider-electric
    Product
    Quantum Ethernet Module 140cpu65260
    Vendor
    Schneider-electric
    Product
    Quantum Ethernet Module 140noe77100
    Vendor
    Schneider-electric
    Product
    Quantum Ethernet Module 140noe77101
    Vendor
    Schneider-electric
    Product
    Quantum Ethernet Module 140noe77111
    Vendor
    Schneider-electric
    Product
    Stb Dio Ethernet Module Stbnic2212
    Vendor
    Schneider-electric
    Product
    Stb Dio Ethernet Module Stbnip2212
    Vendor
    Schneider-electric
    Product
    Stb Dio Ethernet Module Stbnip2311

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High