**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4.
**VERSION NO SOPORTADA CUANDO SE ASIGNÓ** Una cuenta de puerto de depuración heredada en los TCM instalados en sistema Tricon versiones 10.2.0 hasta 10.5.3, es visible en la red y podría permitir un acceso inapropiado. Esta vulnerabilidad es corregida en TCM versión 10.5.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
AV:N/AC:L/Au:N/C:P/I:N/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | NONE |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | tricon_tcm_4351_firmware | * | <built-in method update of dict object at 0x7e60e8c7ffc0> | Operating System |
| schneider-electric | tricon_tcm_4352_firmware | * | <built-in method update of dict object at 0x7e60e8c7c1c0> | Operating System |
| schneider-electric | tricon_tcm_4351a_firmware | * | <built-in method update of dict object at 0x7e60e8c7e8c0> | Operating System |
| schneider-electric | tricon_tcm_4351b_firmware | * | <built-in method update of dict object at 0x7e60ba0acb00> | Operating System |
| schneider-electric | tricon_tcm_4352a_firmware | * | <built-in method update of dict object at 0x7e60ba0ac300> | Operating System |
| schneider-electric | tricon_tcm_4352b_firmware | * | <built-in method update of dict object at 0x7e60ba0ae700> | Operating System |
| schneider-electric | tristation_1131_firmware | * | <built-in method update of dict object at 0x7e60ba0af540> | Operating System |
| schneider-electric | tristation_1131_firmware | * | <built-in method update of dict object at 0x7e60ba0ae400> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tricon_tcm_4351:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tricon_tcm_4352:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tricon_tcm_4351a:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tricon_tcm_4351b:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tricon_tcm_4352a:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tricon_tcm_4352b:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tristation_1131_firmware:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:schneider-electric:tristation_1131_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tristation_1131:-:*:*:*:*:*:*:* |