« Volver al listado

CVE-2011-4860

Estado: ModificadaAlta (10)—

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4860",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-12-17T11:55:12.307",
  "references": [
    {
      "url": "http://reversemode.com/index.php?option=com_content&task=view&id=80&Itemid=1",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://reversemode.com/index.php?option=com_content&task=view&id=80&Itemid=1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message."
    },
    {
      "lang": "es",
      "value": "La función ComputePassword del módulo Schneider Electric Quantum Ethernet del dispositivo NOE 771 (modulo Quantum 140NOE771*) genera la contraseña de la cuenta fwupgrade realizando un cálculo con la dirección MAC, lo que facilita a atacantes remotos obtener acceso a través de (1) un mensaje de petición ARP o (2) un mensaje de descubrimiento de elementos en la misma red (\"Neighbor Solicitation\")."
    }
  ],
  "lastModified": "2026-06-16T23:35:31.620",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:schneider-electric:quantum_ethernet_module_140noe77100:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E2B9B12-772E-45B0-B696-9487C5EC9669",
              "versionEndIncluding": "3.3"
            },
            {
              "criteria": "cpe:2.3:a:schneider-electric:quantum_ethernet_module_140noe77100:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84E9206F-0AED-4C42-849E-F8741C070234",
              "versionEndIncluding": "3.4"
            },
            {
              "criteria": "cpe:2.3:a:schneider-electric:quantum_ethernet_module_140noe77101:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6272D36-A9E3-4210-8998-19D65323E085",
              "versionEndIncluding": "4.9"
            },
            {
              "criteria": "cpe:2.3:a:schneider-electric:quantum_ethernet_module_140noe77111:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0780C449-C9A7-4D83-9090-C48EB308F69F",
              "versionEndIncluding": "5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}