Lucene search

K
cvelistIcscertCVELIST:CVE-2017-9635
HistoryJun 30, 2017 - 12:00 a.m.

CVE-2017-9635

2017-06-3000:00:00
CWE-326
icscert
www.cve.org

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.3%

Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm could be exploited to reverse the user’s password. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

CNA Affected

[
  {
    "product": "Ampla MES",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "versions 6.4 and prior"
      }
    ]
  }
]

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.3%

Related for CVELIST:CVE-2017-9635