Cleartext Credential Storage in Schneider Electric InduSoft Web Studio and InTouch Machine Edition
CVE-2015-0999
Currently unrated
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 29 March 2015
Summary
Schneider Electric's InduSoft Web Studio and InTouch Machine Edition prior to specific updates are affected by a vulnerability that stores OPC User credentials in cleartext within configuration files. This security flaw allows local users to access sensitive information by simply reading these files, which can lead to unauthorized access to the system. It is essential for users of these products to be aware of this issue and apply the necessary patches to mitigate the risk of credential exposure.
References
Timeline
Vulnerability published
Vulnerability Reserved