CVE-2017-5160

MEDIUM

Aveva Wonderware Intouch Access Anywhere < 11.5.2 - Weak Encryption

Title source: rule

Description

An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.

Scores

CVSS v3 5.3
EPSS 0.0011
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-326
Status published

Affected Products (2)

aveva/wonderware_intouch_access_anywhere < 11.5.2
n/a/Schneider Electric Wonderware InTouch Access Anywhere < Schneider Electric Wonderware InTouch Access Anywhere

Timeline

Published Apr 20, 2017
Tracked Since Feb 18, 2026