CVE-2015-0998

Severity
3.3LOW
EPSS
0.2%
top 54.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 29
Latest updateMay 13

Description

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS vector

AV:A/AC:L/C:P/I:N/A:NExploitability: 6.5 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g465-mm63-2p8q: Schneider Electric InduSoft Web Studio before 72022-05-13
CVEList
CVE-2015-0998: Schneider Electric InduSoft Web Studio before 72015-03-29

💥Exploits & PoCs

1
Exploit-DB
FreeBSD - Multiple Vulnerabilities2015-01-29
CVE-2015-0998 (LOW CVSS 3.3) | Schneider Electric InduSoft Web Stu | cvebase.io