CVE-2019-6812

HIGH

BMX-NOR-0200H Firmware - Use of Hard-coded Credentials via FTP Protocol

Title source: llm
STIX 2.1

Description

A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confidentiality issue when using FTP protocol.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://security.cse.iitk.ac.in/responsible-disclosure

Scores

CVSS v3 7.2
EPSS 0.0031
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
schneider-electric/bmx-nor-0200h_firmware 1.7 ir17 (2 CPE variants)
Published May 22, 2019
Tracked Since Feb 18, 2026