CVE-2011-4859

critical
Published 2011-12-17 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
schneider-electricquantum_ethernet_module_140cpu65150{"endIncluding":"3.5"}
schneider-electricquantum_ethernet_module_140cpu65160{"endIncluding":"3.5"}
schneider-electricquantum_ethernet_module_140cpu65260{"endIncluding":"3.5"}
schneider-electricquantum_ethernet_module_140noe77100{"endIncluding":"3.3"}
schneider-electricquantum_ethernet_module_140noe77101{"endIncluding":"4.9"}
schneider-electricquantum_ethernet_module_140noe77111{"endIncluding":"5.0"}
schneider-electricpremium_ethernet_module_tsxety4103{"endIncluding":"5.0"}
schneider-electricpremium_ethernet_module_tsxety5103{"endIncluding":"5.0"}
schneider-electricpremium_ethernet_module_tsxp57163m{"endIncluding":"4.9"}
schneider-electricpremium_ethernet_module_tsxp572634m{"endIncluding":"4.9"}
schneider-electricpremium_ethernet_module_tsxp573634m{"endIncluding":"4.9"}
schneider-electricpremium_ethernet_module_tsxp574634m{"endIncluding":"3.5"}
schneider-electricpremium_ethernet_module_tsxp575634m{"endIncluding":"3.5"}
schneider-electricpremium_ethernet_module_tsxp576634m{"endIncluding":"3.5"}
schneider-electricm340_ethernet_module_bmxnoe0100{"endIncluding":"2.3"}
schneider-electricm340_ethernet_module_bmxnoe0110{"endIncluding":"4.65"}
schneider-electricm340_ethernet_module_bmxp342020{"endIncluding":"2.2"}
schneider-electricm340_ethernet_module_bmxp342030{"endIncluding":"2.2"}
schneider-electricstb_dio_ethernet_module_stbnic2212{"endIncluding":"2.10"}
schneider-electricstb_dio_ethernet_module_stbnip2212{"endIncluding":"2.73"}
schneider-electricstb_dio_ethernet_module_stbnip2311{"endIncluding":"3.01"}

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.