Cleartext Credential Storage in Schneider Electric InduSoft Web Studio and InTouch Machine Edition
CVE-2015-0999

Currently unrated

Key Information:

Vendor
CVE Published:
29 March 2015

Summary

Schneider Electric's InduSoft Web Studio and InTouch Machine Edition prior to specific updates are affected by a vulnerability that stores OPC User credentials in cleartext within configuration files. This security flaw allows local users to access sensitive information by simply reading these files, which can lead to unauthorized access to the system. It is essential for users of these products to be aware of this issue and apply the necessary patches to mitigate the risk of credential exposure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.