CVE-2017-9637
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.
Schneider Electric Ampla MES 6.4 proporciona capacidades para interactuar con datos de bases de datos de terceros. Cuando la conectividad a esas bases de datos se configura para emplear un nombre de usuario y contraseña SQL, un atacante podría ser capaz de rastrear detalles de la cadena de conexión. Schneider Electric recomienda que los usuarios de Ampla MES en versiones 6.4 y anteriores actualicen a la versión 6.5 de Ampla MES tan pronto como les sea posible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-06-14 CVE Reserved
- 2018-05-18 CVE Published
- 2023-05-12 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/99469 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-187-05 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000118 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Ampla Manufacturing Execution System Search vendor "Schneider-electric" for product "Ampla Manufacturing Execution System" | <= 6.4 Search vendor "Schneider-electric" for product "Ampla Manufacturing Execution System" and version " <= 6.4" | - |
Affected
|