CVE Vulnerabilities

CVE-2014-5412

Improper Authentication

Published: Sep 18, 2014 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ClearscadaAveva2010-r3 (including)2010-r3 (including)
ClearscadaAveva2010-r3.1 (including)2010-r3.1 (including)
ClearscadaAveva2013-r1 (including)2013-r1 (including)
ClearscadaAveva2013-r1.1 (including)2013-r1.1 (including)
ClearscadaAveva2013-r1.1a (including)2013-r1.1a (including)
ClearscadaAveva2013-r1.2 (including)2013-r1.2 (including)
ClearscadaAveva2013-r2 (including)2013-r2 (including)
Scada_expert_clearscadaSchneider-electric2013-r2.1 (including)2013-r2.1 (including)
Scada_expert_clearscadaSchneider-electric2014-r1 (including)2014-r1 (including)

Potential Mitigations

References