Описание
Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.
Ссылки
- Broken LinkVendor Advisory
- Third Party AdvisoryUS Government Resource
- Broken LinkVendor Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.15 (исключая)
cpe:2.3:a:schneider-electric:struxureware_building_expert_multi-purpose_management:*:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00264
Низкий
5 Medium
CVSS2
Дефекты
CWE-522
Связанные уязвимости
github
больше 3 лет назад
Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.
EPSS
Процентиль: 50%
0.00264
Низкий
5 Medium
CVSS2
Дефекты
CWE-522