CVE-2019-6814

A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:net5501_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:net5501:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:net5501-i_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:net5501-i:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:net5501-xt_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:net5501-xt:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:net5504_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:net5504:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:net5500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:net5500:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:net5516_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:net5516:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:schneider-electric:net5508_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:net5508:-:*:*:*:*:*:*:*

History

03 Sep 2022, 03:47

Type Values Removed Values Added
References (MISC) https://www.se.com/ww/en/download/document/SEVD-2019-134-01/ - (MISC) https://www.se.com/ww/en/download/document/SEVD-2019-134-01/ - Vendor Advisory

19 Apr 2021, 13:15

Type Values Removed Values Added
References
  • {'url': 'https://www.schneider-electric.com/en/download/document/SEVD-2019-134-01/', 'name': 'https://www.schneider-electric.com/en/download/document/SEVD-2019-134-01/', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • {'url': 'http://packetstormsecurity.com/files/153782/Schneider-Electric-Pelco-Endura-NET55XX-Encoder.html', 'name': 'http://packetstormsecurity.com/files/153782/Schneider-Electric-Pelco-Endura-NET55XX-Encoder.html', 'tags': ['Third Party Advisory', 'VDB Entry'], 'refsource': 'MISC'}
  • (MISC) https://www.se.com/ww/en/download/document/SEVD-2019-134-01/ -
Summary An Improper Access Control: CWE-284 vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI. A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.

Information

Published : 2019-05-22 20:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-6814

Mitre link : CVE-2019-6814

CVE.ORG link : CVE-2019-6814


JSON object : View

Products Affected

schneider-electric

  • net5501-i_firmware
  • net5500
  • net5508_firmware
  • net5508
  • net5500_firmware
  • net5501
  • net5501-i
  • net5516_firmware
  • net5501-xt
  • net5501_firmware
  • net5501-xt_firmware
  • net5504_firmware
  • net5516
  • net5504
CWE
CWE-287

Improper Authentication