CVE Vulnerabilities

CVE-2015-3974

Published: Sep 28, 2015 | Modified: Sep 29, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/EasyIO, Honeywell Automation India, Johnson Controls, SyxthSENSE, Transformative Wave Technologies, Tridium Asia Pacific, and Tridium Europe products, have a hardcoded password, which makes it easier for remote attackers to obtain access via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Easyio-30p-sf_firmware Easyio * 0.5.20 (including)
Easyio-30p-sf_firmware Easyio * 2.0.5.20 (including)

References