Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-5413

Опубликовано: 18 сент. 2014
Источник: nvd
CVSS2: 6.4
CVSS2: 5
EPSS Низкий

Описание

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:aveva:clearscada:2010:r3:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2010:r3.1:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2013:r1:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2013:r1.1:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2013:r1.1a:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2013:r1.2:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2013:r2:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:scada_expert_clearscada:2013:r2.1:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:scada_expert_clearscada:2014:r1:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00314
Низкий

6.4 Medium

CVSS2

5 Medium

CVSS2

Дефекты

CWE-310
CWE-310

Связанные уязвимости

github
больше 3 лет назад

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.

EPSS

Процентиль: 54%
0.00314
Низкий

6.4 Medium

CVSS2

5 Medium

CVSS2

Дефекты

CWE-310
CWE-310