Show filters
66 Total Results
Displaying 51-60 of 66
Sort by:
Attacker Value
Unknown

CVE-2017-6021

Disclosure Date: May 14, 2018 (last updated November 26, 2024)
In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
0
Attacker Value
Unknown

CVE-2017-9962

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon.
0
Attacker Value
Unknown

CVE-2017-5158

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.
Attacker Value
Unknown

CVE-2017-5156

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.
Attacker Value
Unknown

CVE-2017-5160

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.
Attacker Value
Unknown

CVE-2015-0999

Disclosure Date: March 29, 2015 (last updated October 05, 2023)
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file.
0
Attacker Value
Unknown

CVE-2015-0996

Disclosure Date: March 29, 2015 (last updated October 05, 2023)
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.
0
Attacker Value
Unknown

CVE-2015-0998

Disclosure Date: March 29, 2015 (last updated October 05, 2023)
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
0
Attacker Value
Unknown

CVE-2015-0997

Disclosure Date: March 29, 2015 (last updated October 05, 2023)
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.
0
Attacker Value
Unknown

CVE-2014-5412

Disclosure Date: September 18, 2014 (last updated October 05, 2023)
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.
0