Lucene search

K
cve[email protected]CVE-2014-5412
HistorySep 18, 2014 - 10:55 a.m.

CVE-2014-5412

2014-09-1810:55:11
CWE-264
web.nvd.nist.gov
28
cve-2014-5412
schneider electric
scada
security vulnerability
clearscada 2010 r3
clearscada 2014 r1
remote access
guest account

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.8%

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.

Affected configurations

NVD
Node
avevaclearscadaMatch2010r3
OR
avevaclearscadaMatch2010r3.1
OR
avevaclearscadaMatch2013r1
OR
avevaclearscadaMatch2013r1.1
OR
avevaclearscadaMatch2013r1.1a
OR
avevaclearscadaMatch2013r1.2
OR
avevaclearscadaMatch2013r2
OR
schneider-electricscada_expert_clearscadaMatch2013r2.1
OR
schneider-electricscada_expert_clearscadaMatch2014r1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.8%