CVE-2015-1002 describes a vulnerability in IniNet embeddedWebServer (eWebServer) versions prior to 2.02, impacting IniNet Solutions SCADA Web Server. This flaw stems from improper URL encoding, allowing unauthenticated remote attackers to write to or delete arbitrary files. With a CVSS score of 6.4 (medium severity), it presents a low-complexity attack vector with potential for partial integrity and availability impact. While no public exploits or active exploitation have been identified, and community discussion is minimal, its presence in a SCADA environment warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ininet_solutions:scada_web_server:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.