PT-2015-6361 · Schneider Electric · Struxureware Building Expert Mpm

Artyom Kurbatov

·

Published

2015-09-18

·

Updated

2022-02-02

·

CVE-2015-3962

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Schneider Electric StruxureWare Building Expert MPM versions prior to 2.15
Description The issue concerns the lack of encryption for the client-server data stream, allowing remote attackers to discover credentials by sniffing the network.
Recommendations For versions prior to 2.15, update to version 2.15 or later to enable encryption for the client-server data stream.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3962

Affected Products

Struxureware Building Expert Mpm