A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and AccuSine PCSn (Versions prior to V2.2.4) that could allow an authenticated attacker to access the device via FTP protocol.
2021-09-02T17:15:08.393
2024-11-21T05:50:40.907
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | accusine_pcsp_pfvp_firmware | < 001.006.007 | Yes |
Hardware | schneider-electric | accusine_pcs\+ | - | No |
Hardware | schneider-electric | accusine_pfv\+ | - | No |
Operating System | schneider-electric | accusine_pcsn_active_harmonic_filter_firmware | < 002.002.004 | Yes |
Hardware | schneider-electric | accusine_pcsn | - | No |