2.1
CVE-2014-2381
- EPSS 0.03%
- Veröffentlicht 28.08.2014 01:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Schneider Electric Wonderware Inadequate Encryption Strength
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Invensys ≫ Wonderware Information Server Version4.0 Updatesp1
Invensys ≫ Wonderware Information Server Version4.0 Updatesp1 SwEditionportal
Invensys ≫ Wonderware Information Server Version4.5 Update- Editionportal
Invensys ≫ Wonderware Information Server Version5.0 Update- Editionportal
Invensys ≫ Wonderware Information Server Version5.5 SwEditionportal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.076 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
| ics-cert@hq.dhs.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.