CVE-2015-0999

Severity
2.1LOW
EPSS
0.1%
top 80.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 29
Latest updateMay 13

Description

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w5xj-jgc6-7cv5: Schneider Electric InduSoft Web Studio before 72022-05-13
CVEList
CVE-2015-0999: Schneider Electric InduSoft Web Studio before 72015-03-29

💥Exploits & PoCs

1
Exploit-DB
Sendio ESP - Information Disclosure2015-05-26
CVE-2015-0999 (LOW CVSS 2.1) | Schneider Electric InduSoft Web Stu | cvebase.io