CVE-2014-5413

CWE-3103 documents3 sources
Severity
5.0MEDIUM
EPSS
0.3%
top 45.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 14

Description

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages4 packages

CVEListV5schneider_electric/clearscada2010 R3 (build 72.4560), 2010 R3.1 (build 72.4644)+1
NVDaveva/clearscada2010, 2013+1

🔴Vulnerability Details

2
GHSA
GHSA-wxww-p46r-jjv2: Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X2022-05-14
CVEList
Schneider Electric SCADA Expert ClearSCADA Cryptographic Issues2014-09-18
CVE-2014-5413 (MEDIUM CVSS 5) | Schneider Electric StruxureWare SCA | cvebase.io