CVE-2014-2380
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
28/08/2014
Last modified:
01/11/2025
Description
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.
Impact
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:invensys:wonderware_information_server:4.0:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:invensys:wonderware_information_server:4.0:sp1:*:*:portal:*:*:* | ||
| cpe:2.3:a:invensys:wonderware_information_server:4.5:-:portal:*:*:*:*:* | ||
| cpe:2.3:a:invensys:wonderware_information_server:5.0:-:portal:*:*:*:*:* | ||
| cpe:2.3:a:invensys:wonderware_information_server:5.5:*:*:*:portal:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



