VYPR
Unrated severityNVD Advisory· Published Jan 23, 2020· Updated Aug 6, 2024

CVE-2012-6663

CVE-2012-6663

Description

General Electric D20ME devices expose plaintext passwords via TFTP due to misconfiguration, allowing remote attackers to gain credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

General Electric D20ME devices expose plaintext passwords via TFTP due to misconfiguration, allowing remote attackers to gain credentials.

Vulnerability

The General Electric D20ME (and possibly D200) devices are shipped with a misconfiguration that exposes plaintext passwords in a TFTP-accessible configuration file. The vulnerability exists because the device does not enforce authentication or encryption for TFTP reads, allowing anyone with network access to retrieve the configuration. Affected versions include the D20ME and potentially other units in the same family, as noted in the Metasploit module [1].

Exploitation

An attacker needs only network access to the device's TFTP service (typically UDP port 69). No authentication or prior access is required. The attacker can use a TFTP client to request the configuration file, which contains the username, password, and authentication level list in plaintext. The Metasploit module auxiliary/gather/d20pass automates this process [1].

Impact

Successful exploitation yields a list of plaintext credentials, including usernames and passwords. An attacker can then use these credentials to log into the device with the corresponding privilege level, potentially gaining administrative access to the industrial control system. This compromises the confidentiality and integrity of the device and the network it controls.

Mitigation

No official patch or firmware update has been disclosed in the available references [1]. As a workaround, operators should disable the TFTP service if not required, restrict network access to the device via firewall rules, or implement network segmentation to limit exposure. If TFTP is necessary, consider using a VPN or other encrypted tunnel to protect the configuration transfer.

References
  1. Rapid7

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.