CVE-2015-7911
Status: ModifiedCritical (9.1)—
Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.24.41 have hardcoded credentials, which allows remote attackers to obtain administrative access via an FTP session.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Base score: 9.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.42%
- Percentile among all scored CVEs: 84
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (14)
Saia Burgess Controls — Pcd1.m0xx0 FirmwareSaia Burgess Controls — Pcd1.m2xx0 FirmwareSaia Burgess Controls — Pcd2.m5xx0 FirmwareSaia Burgess Controls — Pcd3.mxx60 FirmwareSaia Burgess Controls — Pcd3.mxxx0 FirmwareSaia Burgess Controls — Pcd3.t665 FirmwareSaia Burgess Controls — Pcd3.t666 FirmwareSaia Burgess Controls — Pcd7.d4xxd FirmwareSaia Burgess Controls — Pcd7.d4xxd Svga MB FirmwareSaia Burgess Controls — Pcd7.d4xxv FirmwareSaia Burgess Controls — Pcd7.d4xxv VGA MB FirmwareSaia Burgess Controls — Pcd7.d4xxwtpf FirmwareSaia Burgess Controls — Pcd7.d4xxwtpf Wvga MB FirmwareSaia Burgess Controls — Pcd7.d4xxxt5f Firmware
CWEs
- CWE-255
References
Raw JSON (NVD)
Show
{
"id": "CVE-2015-7911",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-12-23T03:59:03.200",
"references": [
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-335-01",
"tags": [
"Patch",
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-15-335-01",
"tags": [
"Patch",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.24.41 have hardcoded credentials, which allows remote attackers to obtain administrative access via an FTP session."
},
{
"lang": "es",
"value": "Dispositivos Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF y PCD7.D4xxxT5F en versiones a anteriores a 1.24.50 y dispositivos PCD3.T665 y PCD3.T666 en versiones a anteriores a 1.24.41 tienen credenciales embebidas, lo que permite a atacantes remotos obtener acceso administrativo a través de una sesión FTP."
}
],
"lastModified": "2026-06-17T00:33:22.570",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxv_vga_mb_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A449695F-D887-467D-A7C8-A49624B2D98D",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxv_vga_mb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AEBFC820-2475-4983-B121-A9218B7CA9A9"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxd_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB31C345-3D42-4AC1-8B67-1C6141C96A24",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxd:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D8DAA1EE-205E-4B74-AA18-214E47BD71D3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.mxxx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3AC536B8-BD04-4247-ADB8-E7D419383D7E",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.mxxx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "331C8AE7-49E2-4EC6-A3D1-4A15E49224B5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxd_svga_mb_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CDF7DA2-0D98-455D-90BB-B52E3115DF0C",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxd_svga_mb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8DF47617-D46D-40B5-979C-97ECCB9AA380"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.t666_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75497879-C207-4E52-A3A4-8D3A3187EDE5",
"versionEndIncluding": "1.24.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.t666:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "45D5750C-6EE7-461C-845D-53B3EB741D65"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd1.m2xx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D176B2BB-EFFB-4686-82D9-42C9DE859F39",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd1.m2xx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FE665886-EF93-4F86-B5AD-B81F1469211F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.mxx60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CE17CB8-BF9F-4133-A00D-37EF2589C087",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.mxx60:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "14DE813D-C8E1-4DD7-8DA3-F6F9E0C7542F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd3.t665_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "781AA257-C343-488E-B918-10C6FD0D7E6F",
"versionEndIncluding": "1.24.30"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd3.t665:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E48B2179-4C04-4698-A9F1-575C45F2B9E4",
"versionEndIncluding": "-"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd2.m5xx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA8B1B34-70A5-48F2-8D72-7888EE00AA66",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd2.m5xx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B2B110DC-6278-49C4-A8D0-299AB9D5D5DE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxwtpf_wvga_mb:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FF730BCA-D3C5-4640-97EB-04D4C495F2DA"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxwtpf_wvga_mb_firmware:1.24.41:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D4E2F09-DD0E-4A3D-B3C6-2A256EF4E1BA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxwtpf_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21F8B944-CBFB-41AF-8227-DD522C9233C1",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxwtpf:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1FB5B2F0-839E-4882-A868-6AB7548D643C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd1.m0xx0_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35A393C4-8865-498B-9885-F9BD26B9D5C4",
"versionEndIncluding": "1.24.25"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd1.m0xx0:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D0D7A81F-EF55-48BF-B9A6-19F9269E20A8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxxt5f_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A23937F1-5686-4EFB-B77B-B8A5B73CF842",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxxt5f:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5D202770-CC48-470B-8442-30BC10521E1D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:saia_burgess_controls:pcd7.d4xxv_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7318A0C-BCF2-4E25-9E00-420E3D876072",
"versionEndIncluding": "1.24.41"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:saia_burgess_controls:pcd7.d4xxv:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7D25D4B6-A9A4-4147-99D4-9F95D8A31B9F"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}