- Description
- EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/EasyIO, Honeywell Automation India, Johnson Controls, SyxthSENSE, Transformative Wave Technologies, Tridium Asia Pacific, and Tridium Europe products, have a hardcoded password, which makes it easier for remote attackers to obtain access via unspecified vectors.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
CVSS 2.0
- Type
- Primary
- Base score
- 9
- Impact score
- 10
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:C/I:C/A:C
- nvd@nist.gov
- CWE-255
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:easyio:easyio-30p-sf_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85F05441-AFE6-47D8-A896-02146670117A",
"versionEndIncluding": "0.5.20"
},
{
"criteria": "cpe:2.3:o:easyio:easyio-30p-sf_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FC6F077-B742-4612-A690-84565E58EEA2",
"versionEndIncluding": "2.0.5.20"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:easyio:easyio-30p-sf:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7834220-395D-4FDA-989D-31A1E5A9C205"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]