HIGH · 7.5

CVE-2014-5396

The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attackers to obtain access v...

Vulnerability Description

The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SchrackTechnik Microcontrol Firmware<= 1.7.0
SchrackTechnik Microcontrol-

References

FAQ

What is CVE-2014-5396?

CVE-2014-5396 is a vulnerability with a CVSS score of 7.5 (HIGH). The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attackers to obtain access v...

How severe is CVE-2014-5396?

CVE-2014-5396 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-5396?

Check the references section above for vendor advisories and patch information. Affected products include: Schrack Technik Microcontrol Firmware, Schrack Technik Microcontrol.