CVE-2015-0996

Schneider Electric InduSoft Web Studio <7.1.3.4 SP3 Patch 4 - Info ...

Title source: llm
STIX 2.1

Description

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-15-085-01

Scores

EPSS 0.0006
EPSS Percentile 19.1%

Details

CWE
CWE-200
Status published
Products (2)
aveva/aveva_edge < 7.1.3.4
schneider-electric/wonderware_intouch_2014 < 7.1.3.4
Published Mar 29, 2015
Tracked Since Feb 18, 2026