CVE-2015-0997
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
29/03/2015
Last modified:
12/04/2025
Description
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:aveva:aveva_edge:*:*:*:*:*:*:*:* | 7.1.3.4 (excluding) | |
| cpe:2.3:a:schneider-electric:wonderware_intouch_2014:*:*:*:*:machine:*:*:* | 7.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-01
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-02
- https://ics-cert.us-cert.gov/advisories/ICSA-15-085-01
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-01
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-02
- https://ics-cert.us-cert.gov/advisories/ICSA-15-085-01



