Vulnerability CVE-2015-6485


Published: 2016-03-11   Modified: 2016-03-12

Description:
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Schneider electric -> Telvent rtu firmware 
Schneider-electric -> Telvent rtu firmware 

 References:
https://ics-cert.us-cert.gov/advisories/ICSA-16-070-01

Copyright 2024, cxsecurity.com

 

Back to Top