CVE-2015-7911

high-risk
Published 2015-12-23

Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.24.41 have hardcoded credentials, which allows remote attackers to obtain administrative access via an FTP session.

Do I need to act?

-
0.75% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.1/10 Critical
NETWORK / LOW complexity

Affected Products (14)

Pcd7.D4Xxv Vga Mb Firmware
Pcd7.D4Xxd Firmware
Pcd3.Mxxx0 Firmware
Pcd3.Mxx60 Firmware
Pcd2.M5Xx0 Firmware
Pcd1.M0Xx0 Firmware
Pcd7.D4Xxxt5F Firmware
Pcd7.D4Xxv Firmware
Pcd7.D4Xxd Svga Mb Firmware
Pcd3.T666 Firmware
Pcd1.M2Xx0 Firmware
Pcd3.T665 Firmware
Pcd7.D4Xxwtpf Wvga Mb Firmware
Pcd7.D4Xxwtpf Firmware

Affected Vendors

52
/ 100
high-risk
Severity 31/34 · Critical
Exploitability 3/34 · Minimal
Exposure 18/34 · Moderate