CVE-2015-7911
Estado: ModificadaCrítica (9.1)—
Dispositivos Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF y PCD7.D4xxxT5F en versiones a anteriores a 1.24.50 y dispositivos PCD3.T665 y PCD3.T666 en versiones a anteriores a 1.24.41 tienen credenciales embebidas, lo que permite a atacantes remotos obtener acceso administrativo a través de una sesión FTP.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.42%
- Percentil entre todas las CVEs puntuadas: 84
- Fecha de la puntuación: 10/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (14)
Saia Burgess Controls — Pcd1.m0xx0 FirmwareSaia Burgess Controls — Pcd1.m2xx0 FirmwareSaia Burgess Controls — Pcd2.m5xx0 FirmwareSaia Burgess Controls — Pcd3.mxx60 FirmwareSaia Burgess Controls — Pcd3.mxxx0 FirmwareSaia Burgess Controls — Pcd3.t665 FirmwareSaia Burgess Controls — Pcd3.t666 FirmwareSaia Burgess Controls — Pcd7.d4xxd FirmwareSaia Burgess Controls — Pcd7.d4xxd Svga MB FirmwareSaia Burgess Controls — Pcd7.d4xxv FirmwareSaia Burgess Controls — Pcd7.d4xxv VGA MB FirmwareSaia Burgess Controls — Pcd7.d4xxwtpf FirmwareSaia Burgess Controls — Pcd7.d4xxwtpf Wvga MB FirmwareSaia Burgess Controls — Pcd7.d4xxxt5f Firmware
CWE
- CWE-255
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-7911",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-12-23T03:59:03.200",
"references": [
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-335-01",
"tags": [
"Patch",
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-335-01",
"tags": [
"Patch",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.24.41 have hardcoded credentials, which allows remote attackers to obtain administrative access via an FTP session."
},
{
"lang": "es",
"value": "Dispositivos Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF y PCD7.D4xxxT5F en versiones a anteriores a 1.24.50 y dispositivos PCD3.T665 y PCD3.T666 en versiones a anteriores a 1.24.41 tienen credenciales embebidas, lo que permite a atacantes remotos obtener acceso administrativo a través de una sesión FTP."
}
],
"lastModified": "2026-06-17T00:33:22.570",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxv_vga_mb_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A449695F-D887-467D-A7C8-A49624B2D98D",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxv_vga_mb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AEBFC820-2475-4983-B121-A9218B7CA9A9"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxd_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB31C345-3D42-4AC1-8B67-1C6141C96A24",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxd:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D8DAA1EE-205E-4B74-AA18-214E47BD71D3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.mxxx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3AC536B8-BD04-4247-ADB8-E7D419383D7E",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.mxxx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "331C8AE7-49E2-4EC6-A3D1-4A15E49224B5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxd_svga_mb_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CDF7DA2-0D98-455D-90BB-B52E3115DF0C",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxd_svga_mb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8DF47617-D46D-40B5-979C-97ECCB9AA380"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.t666_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75497879-C207-4E52-A3A4-8D3A3187EDE5",
"versionEndIncluding": "1.24.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.t666:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "45D5750C-6EE7-461C-845D-53B3EB741D65"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd1.m2xx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D176B2BB-EFFB-4686-82D9-42C9DE859F39",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd1.m2xx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FE665886-EF93-4F86-B5AD-B81F1469211F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.mxx60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CE17CB8-BF9F-4133-A00D-37EF2589C087",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.mxx60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "14DE813D-C8E1-4DD7-8DA3-F6F9E0C7542F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.t665_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "781AA257-C343-488E-B918-10C6FD0D7E6F",
"versionEndIncluding": "1.24.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.t665:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E48B2179-4C04-4698-A9F1-575C45F2B9E4",
"versionEndIncluding": "-"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd2.m5xx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA8B1B34-70A5-48F2-8D72-7888EE00AA66",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd2.m5xx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B2B110DC-6278-49C4-A8D0-299AB9D5D5DE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxwtpf_wvga_mb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FF730BCA-D3C5-4640-97EB-04D4C495F2DA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxwtpf_wvga_mb_firmware:1.24.41:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D4E2F09-DD0E-4A3D-B3C6-2A256EF4E1BA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxwtpf_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21F8B944-CBFB-41AF-8227-DD522C9233C1",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxwtpf:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1FB5B2F0-839E-4882-A868-6AB7548D643C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd1.m0xx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35A393C4-8865-498B-9885-F9BD26B9D5C4",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd1.m0xx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D0D7A81F-EF55-48BF-B9A6-19F9269E20A8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxxt5f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A23937F1-5686-4EFB-B77B-B8A5B73CF842",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxxt5f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5D202770-CC48-470B-8442-30BC10521E1D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxv_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7318A0C-BCF2-4E25-9E00-420E3D876072",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxv:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7D25D4B6-A9A4-4147-99D4-9F95D8A31B9F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}