CVE-2014-5412

Severity
5.0MEDIUM
EPSS
0.5%
top 32.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 14

Description

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages4 packages

CVEListV5schneider_electric/clearscada2010 R3 (build 72.4560), 2010 R3.1 (build 72.4644)+1
NVDaveva/clearscada2010, 2013+1

🔴Vulnerability Details

2
GHSA
GHSA-q6fc-f6x3-vfx6: Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access2022-05-14
CVEList
Schneider Electric SCADA Expert ClearSCADA Improper Authentication2014-09-18
CVE-2014-5412 (MEDIUM CVSS 5) | Schneider Electric StruxureWare SCA | cvebase.io