CVE-2014-2381
ICS-CERT Advisory - Schneider Electric Wonderware
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 hasta 5.5 utiliza codificaciones débiles, lo que permite a usuarios locales obtener información sensible mediante la lectura de un fichero de credenciales.
Timur Yunusov, Ilya Karpov, Sergey Gordeychik, Alexey Osipov, and Dmitry Serebryannikov of the Positive Technologies Research Team have identified four vulnerabilities in the Schneider Electric Wonderware Information Server (WIS). Schneider Electric has produced an update that mitigates these vulnerabilities. Some of these vulnerabilities could be exploited remotely.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-03-13 CVE Reserved
- 2014-08-28 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-14-238-02 | Us Government Resource |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 4.0 Search vendor "Invensys" for product "Wonderware Information Server" and version "4.0" | sp1 |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 4.0 Search vendor "Invensys" for product "Wonderware Information Server" and version "4.0" | sp1, portal |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 4.5 Search vendor "Invensys" for product "Wonderware Information Server" and version "4.5" | portal |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 5.0 Search vendor "Invensys" for product "Wonderware Information Server" and version "5.0" | portal |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 5.5 Search vendor "Invensys" for product "Wonderware Information Server" and version "5.5" | portal |
Affected
|