CVE-2015-0996
Last modified
CVE-2015-0996 is a vulnerability of currently unknown severity. Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Aveva | Aveva Edge | < 7.1.3.4 |
| Schneider-Electric | Wonderware Intouch 2014 | < 7.1.3.4 |
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-01Patch, Vendor Advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-02Patch, Vendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-085-01Third Party Advisory, US Government Resource
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-01Patch, Vendor Advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-054-02Patch, Vendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-085-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0996?
How severe is CVE-2015-0996?
How do I fix CVE-2015-0996?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0990Untrusted search path vulnerability in Ecava IntegraXor SCAD…
- CVE-2015-0991Inductive Automation Ignition 7.7.2 allows remote attackers …
- CVE-2015-0992Inductive Automation Ignition 7.7.2 stores cleartext OPC Ser…
- CVE-2015-0993Inductive Automation Ignition 7.7.2 does not terminate a ses…
- CVE-2015-0994Inductive Automation Ignition 7.7.2 allows remote authentica…
- CVE-2015-0995Inductive Automation Ignition 7.7.2 uses MD5 password hashes…
- CVE-2015-0997Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Pa…
- CVE-2015-0998Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Pa…
- CVE-2015-0999Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Pa…
- CVE-2015-1000Stack-based buffer overflow in the OpenForIPCamTest method i…
- CVE-2015-1000000Remote file upload vulnerability in mailcwp v1.99 wordpress …
- CVE-2015-1000001Remote file upload vulnerability in fast-image-adder v1.1 Wo…
Are you affected by CVE-2015-0996?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
