Описание
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.
Ссылки
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- MitigationThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:schneider-electric:wonderware_historian:2014_r2_sp1_p01:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00642
Низкий
7.3 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1188
Связанные уязвимости
CVSS3: 7.3
github
больше 3 лет назад
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.
EPSS
Процентиль: 70%
0.00642
Низкий
7.3 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-1188