CVE Vulnerabilities

CVE-2015-3962

Insufficiently Protected Credentials

Published: Sep 18, 2015 | Modified: Feb 02, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Struxureware_building_expert_multi-purpose_management Schneider-electric * 2.15 (excluding)

Potential Mitigations

References