CVE-2015-0997

Severity
5.0MEDIUM
EPSS
0.6%
top 30.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 29
Latest updateMay 13

Description

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jf3r-fxmm-grph: Schneider Electric InduSoft Web Studio before 72022-05-13
CVEList
CVE-2015-0997: Schneider Electric InduSoft Web Studio before 72015-03-29

💥Exploits & PoCs

1
Exploit-DB
Android WiFi-Direct - Denial of Service2015-01-26
CVE-2015-0997 (MEDIUM CVSS 5) | Schneider Electric InduSoft Web Stu | cvebase.io