CVE-2017-5155 describes a vulnerability in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier, where the software creates logins with default, easily guessable passwords. This flaw allows an unauthenticated attacker to compromise Historian databases and potentially other connected resources. With a CVSS v3 score of 7.3 (High), the vulnerability is easily exploitable over the network with low attack complexity, leading to potential loss of confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and there is no evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2014_r2_sp1_p01CPE matchmatch criteria | cpe:2.3:a:schneider-electric:wonderware_historian:2014_r2_sp1_p01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.