Lucene search

K
cvelistIcscertCVELIST:CVE-2017-9637
HistoryJun 30, 2017 - 12:00 a.m.

CVE-2017-9637

2017-06-3000:00:00
CWE-319
icscert
www.cve.org

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.1%

Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

CNA Affected

[
  {
    "product": "Ampla MES",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "versions 6.4 and prior"
      }
    ]
  }
]

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.1%

Related for CVELIST:CVE-2017-9637