MidnightBSD

Advisories for saia_burgess_controls

CVE-2015-7911 HIGH

Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.24.41 have hardcoded credentials, which allows remote attackers to obtain administrative access via an FTP session.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-255,

Products Affected

Vendor Product Version
saia_burgess_controls pcd3.t666_firmware *
saia_burgess_controls pcd3.mxxx0_firmware *
saia_burgess_controls pcd7.d4xxv_vga_mb_firmware *
saia_burgess_controls pcd2.m5xx0_firmware *
saia_burgess_controls pcd3.t665_firmware *
saia_burgess_controls pcd7.d4xxd_firmware *
saia_burgess_controls pcd7.d4xxxt5f_firmware *
saia_burgess_controls pcd3.mxx60_firmware *
saia_burgess_controls pcd7.d4xxwtpf_firmware *
saia_burgess_controls pcd7.d4xxwtpf_wvga_mb_firmware 1.24.41
saia_burgess_controls pcd1.m2xx0_firmware *
saia_burgess_controls pcd7.d4xxv_firmware *
saia_burgess_controls pcd1.m0xx0_firmware *
saia_burgess_controls pcd7.d4xxd_svga_mb_firmware *
CVE-2017-9628 MEDIUM

An Information Exposure issue was discovered in Saia Burgess Controls PCD Controllers with PCD firmware versions prior to 1.28.16 or 1.24.69. In certain circumstances, the device pads Ethernet frames with memory contents.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,CWE-200,

Products Affected

Vendor Product Version
saia_burgess_controls pcd_controllers_firmware *