// For flags

CVE-2015-6485

 

Severity Score

5.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.

Schneider Electric Telvent Sage 2300 RTUs con firmware anterior a C3413-500-S01 y LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400 y Sage 3030M RTUs con firmware anterior a C3414-500-S02J2, permiten a atacantes remotos obtener informaciĆ³n sensible de memoria del dispositivo leyendo un campo de relleno de un paquete Ethernet.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-08-17 CVE Reserved
  • 2016-03-12 CVE Published
  • 2024-01-02 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Schneider-electric
Search vendor "Schneider-electric"
Telvent Rtu Firmware
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware"
<= c3414-500-s02j1
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware" and version " <= c3414-500-s02j1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Sage 1410
Search vendor "Schneider-electric" for product "Sage 1410"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Telvent Rtu Firmware
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware"
<= c3414-500-s02j1
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware" and version " <= c3414-500-s02j1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Sage 1430
Search vendor "Schneider-electric" for product "Sage 1430"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Telvent Rtu Firmware
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware"
<= c3414-500-s02j1
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware" and version " <= c3414-500-s02j1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Sage 1450
Search vendor "Schneider-electric" for product "Sage 1450"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Telvent Rtu Firmware
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware"
<= c3414-500-s02j1
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware" and version " <= c3414-500-s02j1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Sage 2400
Search vendor "Schneider-electric" for product "Sage 2400"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Telvent Rtu Firmware
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware"
<= c3414-500-s02j1
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware" and version " <= c3414-500-s02j1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Sage 3030m
Search vendor "Schneider-electric" for product "Sage 3030m"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Telvent Rtu Firmware
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware"
<= c3414-500-s02j1
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware" and version " <= c3414-500-s02j1"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Sage Landac Ii-2
Search vendor "Schneider-electric" for product "Sage Landac Ii-2"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Telvent Rtu Firmware
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware"
<= c3413-500-001d3
Search vendor "Schneider-electric" for product "Telvent Rtu Firmware" and version " <= c3413-500-001d3"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Sage 2300
Search vendor "Schneider-electric" for product "Sage 2300"
--
Safe