CVE-2014-5396

The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attackers to obtain access via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schrack:technik_microcontrol_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schrack:technik_microcontrol:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:11

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2014/Jul/40 - Exploit () http://seclists.org/fulldisclosure/2014/Jul/40 - Exploit
References () https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140710-2_Schrack_Technik_Microcontrol_Multiple_critical_vulnerabilities_v10.txt - Exploit () https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140710-2_Schrack_Technik_Microcontrol_Multiple_critical_vulnerabilities_v10.txt - Exploit

Information

Published : 2014-08-22 14:55

Updated : 2024-11-21 02:11


NVD link : CVE-2014-5396

Mitre link : CVE-2014-5396

CVE.ORG link : CVE-2014-5396


JSON object : View

Products Affected

schrack

  • technik_microcontrol_firmware
  • technik_microcontrol