Vulnerability CVE-2017-5158


Published: 2017-04-20

Description:
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Schneider electric -> Wonderware intouch access anywhere 2014 

 References:
http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000114/
http://www.securityfocus.com/bid/97256
https://ics-cert.us-cert.gov/advisories/ICSA-17-089-01

Copyright 2024, cxsecurity.com

 

Back to Top