CVE-2015-0996
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD
Description
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.
Affected (2)
Products: Aveva: Aveva Edge · Schneider Electric: Wonderware Intouch 2014
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.1.3.4 | |
| Before 7.1.3.4 |
References (6)
Source: ics-cert@hq.dhs.gov
PatchVendor Advisory
Source: ics-cert@hq.dhs.gov
PatchVendor Advisory
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.