2.1
CVE-2014-2381
- EPSS 0.15%
- Veröffentlicht 28.08.2014 01:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Schneider Electric Wonderware Inadequate Encryption Strength
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Invensys ≫ Wonderware Information Server Version 4.0 Update sp1
Invensys ≫ Wonderware Information Server Version 4.0 Update sp1 SwEdition portal
Invensys ≫ Wonderware Information Server Version 4.5 Update - Edition portal
Invensys ≫ Wonderware Information Server Version 5.0 Update - Edition portal
Invensys ≫ Wonderware Information Server Version 5.5 SwEdition portal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.041 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
| DHS.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://ics-cert.us-cert.gov/advisories/ICSA-14-238-02
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2014/icsa-14-238-02.json
https://www.cisa.gov/news-events/ics-advisories/icsa-14-238-02