ID

VAR-201508-0279


CVE

CVE-2015-1009


TITLE

Schneider Electric InduSoft Password storage vulnerability

Trust: 0.8

sources: IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05102

DESCRIPTION

Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file. InduSoft Web Studio is a SCADA system and embedded instrumentation solution for developing human-machine interfaces, supervisory control and data acquisition. Multiple Schneider Electric products are prone to a local information-disclosure vulnerability. Local attackers can exploit this issue to obtain sensitive information which may aid in further attacks. The following products are vulnerable: InduSoft Web Studio 7.1.3.4 and prior InTouch Machine Edition 2014 7.1.3.4 and prior

Trust: 2.61

sources: NVD: CVE-2015-1009 // JVNDB: JVNDB-2015-003985 // CNVD: CNVD-2015-05102 // BID: 76127 // IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05102

AFFECTED PRODUCTS

vendor:indusoftmodel:web studioscope:lteversion:7.1.3.5

Trust: 1.0

vendor:wonderwaremodel:intouchscope:lteversion:7.1

Trust: 1.0

vendor:schneider electricmodel:indusoft web studioscope:ltversion:7.1.3.5 patch 5

Trust: 0.8

vendor:schneider electricmodel:intouch machine edition 2014scope:lteversion:7.1 sp3 patch 4

Trust: 0.8

vendor:schneidermodel:electric indusoft web studio patchscope:ltversion:7.1.3.55

Trust: 0.6

vendor:schneidermodel:electric wonderware intouch machine edition sp3 patchscope:eqversion:7.14

Trust: 0.6

vendor:wonderwaremodel:intouchscope:eqversion:7.1

Trust: 0.6

vendor:schneider electricmodel:intouch machine editionscope:eqversion:20147.1.3.2

Trust: 0.3

vendor:schneider electricmodel:intouch machine edition sp3 patchscope:eqversion:20147.14

Trust: 0.3

vendor:schneider electricmodel:indusoft web studio sp patchscope:eqversion:7.1.3.434

Trust: 0.3

vendor:schneider electricmodel:indusoft web studioscope:eqversion:7.1.3.4

Trust: 0.3

vendor:schneider electricmodel:indusoft web studioscope:eqversion:7.1.3.2

Trust: 0.3

vendor:schneider electricmodel:indusoft web studio patchscope:neversion:7.1.3.55

Trust: 0.3

vendor:web studiomodel: - scope:eqversion:*

Trust: 0.2

vendor:intouchmodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05102 // BID: 76127 // JVNDB: JVNDB-2015-003985 // CNNVD: CNNVD-201507-833 // NVD: CVE-2015-1009

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1009
value: LOW

Trust: 1.0

NVD: CVE-2015-1009
value: LOW

Trust: 0.8

CNVD: CNVD-2015-05102
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201507-833
value: LOW

Trust: 0.6

IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

nvd@nist.gov: CVE-2015-1009
severity: LOW
baseScore: 1.7
vectorString: AV:L/AC:L/AU:S/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-05102
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05102 // JVNDB: JVNDB-2015-003985 // CNNVD: CNNVD-201507-833 // NVD: CVE-2015-1009

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2015-003985 // NVD: CVE-2015-1009

THREAT TYPE

local

Trust: 0.9

sources: BID: 76127 // CNNVD: CNNVD-201507-833

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201507-833

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003985

PATCH

title:SEVD-2015-100-01url:http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-100-01

Trust: 0.8

title:Schneider Electric InduSoft Password Storage Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/61905

Trust: 0.6

title:IWS71.3.5url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=57105

Trust: 0.6

sources: CNVD: CNVD-2015-05102 // JVNDB: JVNDB-2015-003985 // CNNVD: CNNVD-201507-833

EXTERNAL IDS

db:NVDid:CVE-2015-1009

Trust: 3.5

db:ICS CERTid:ICSA-15-211-01

Trust: 3.3

db:SCHNEIDERid:SEVD-2015-100-01

Trust: 1.6

db:CNVDid:CNVD-2015-05102

Trust: 0.8

db:CNNVDid:CNNVD-201507-833

Trust: 0.8

db:JVNDBid:JVNDB-2015-003985

Trust: 0.8

db:BIDid:76127

Trust: 0.3

db:IVDid:80C77FCC-2351-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 80c77fcc-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-05102 // BID: 76127 // JVNDB: JVNDB-2015-003985 // CNNVD: CNNVD-201507-833 // NVD: CVE-2015-1009

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-15-211-01

Trust: 3.3

url:https://gcsresource.invensys.com/support/docs/_securitybulletins/security_bulletin_lfsec00000110.pdf

Trust: 1.6

url:http://download.schneider-electric.com/files?p_doc_ref=sevd-2015-100-01

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1009

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1009

Trust: 0.8

url:http://www.schneider-electric.com/site/home/index.cfm/ww/?selectcountry=true

Trust: 0.3

sources: CNVD: CNVD-2015-05102 // BID: 76127 // JVNDB: JVNDB-2015-003985 // CNNVD: CNNVD-201507-833 // NVD: CVE-2015-1009

CREDITS

Gleb Gritsai, Ilya Karpov, and Kirill Nesterov of Positive Technologies Security Lab.

Trust: 0.3

sources: BID: 76127

SOURCES

db:IVDid:80c77fcc-2351-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2015-05102
db:BIDid:76127
db:JVNDBid:JVNDB-2015-003985
db:CNNVDid:CNNVD-201507-833
db:NVDid:CVE-2015-1009

LAST UPDATE DATE

2024-11-23T22:52:43.048000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-05102date:2015-08-04T00:00:00
db:BIDid:76127date:2015-07-30T00:00:00
db:JVNDBid:JVNDB-2015-003985date:2015-08-05T00:00:00
db:CNNVDid:CNNVD-201507-833date:2015-08-06T00:00:00
db:NVDid:CVE-2015-1009date:2024-11-21T02:24:29.147

SOURCES RELEASE DATE

db:IVDid:80c77fcc-2351-11e6-abef-000c29c66e3ddate:2015-08-04T00:00:00
db:CNVDid:CNVD-2015-05102date:2015-08-04T00:00:00
db:BIDid:76127date:2015-07-30T00:00:00
db:JVNDBid:JVNDB-2015-003985date:2015-08-05T00:00:00
db:CNNVDid:CNNVD-201507-833date:2015-07-31T00:00:00
db:NVDid:CVE-2015-1009date:2015-08-01T01:59:00.067