CVE Vulnerabilities

CVE-2014-5412

Improper Authentication

Published: Sep 18, 2014 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Clearscada Aveva 2010-r3 (including) 2010-r3 (including)
Clearscada Aveva 2010-r3.1 (including) 2010-r3.1 (including)
Clearscada Aveva 2013-r1 (including) 2013-r1 (including)
Clearscada Aveva 2013-r1.1 (including) 2013-r1.1 (including)
Clearscada Aveva 2013-r1.1a (including) 2013-r1.1a (including)
Clearscada Aveva 2013-r1.2 (including) 2013-r1.2 (including)
Clearscada Aveva 2013-r2 (including) 2013-r2 (including)
Scada_expert_clearscada Schneider-electric 2013-r2.1 (including) 2013-r2.1 (including)
Scada_expert_clearscada Schneider-electric 2014-r1 (including) 2014-r1 (including)

Potential Mitigations

References