5
CVSSv2

CVE-2015-0997

Published: 29/03/2015 Updated: 14/05/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Schneider Electric InduSoft Web Studio prior to 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 prior to 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote malicious users to obtain access via a brute-force password-guessing attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aveva aveva edge

schneider-electric wonderware intouch 2014