PT-2017-16349 · Schneider Electric · Wonderware Historian
Publicado
2017-02-13
·
Atualizado
2019-10-03
·
CVE-2017-5155
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Schneider Electric Wonderware Historian versions 2014 R2 SP1 P01 and earlier
Description
An issue was discovered where Wonderware Historian creates logins with default passwords, allowing a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may also be compromised.
Recommendations
For versions 2014 R2 SP1 P01 and earlier, change the default passwords for all logins created by Wonderware Historian to prevent potential compromise of Historian databases and other resources.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wonderware Historian