CVE-2015-0997 describes an information disclosure vulnerability in Schneider Electric InduSoft Web Studio and InTouch Machine Edition 2014, specifically versions before 7.1.3.4 SP3 Patch 4. The HMI user interface in these products inadvertently lists all valid usernames, making it significantly easier for remote attackers to conduct brute-force password-guessing attacks. This vulnerability has a CVSS score of 5.0, indicating a medium severity, with a network attack vector, low attack complexity, and a potential impact of partial confidentiality loss. While there is no known active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, suggesting it is a known issue within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.1.3.4CPE matchmatch criteria | cpe:2.3:a:aveva:aveva_edge:*:*:*:*:*:*:*:* | ||
< 7.1CPE matchmatch criteria | cpe:2.3:a:schneider-electric:wonderware_intouch_2014:*:*:*:*:machine:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.