← Volver a CVEs
CVE-2017-5160
MEDIUM5.3
Descripcion
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.
Detalles CVE
Puntuacion CVSS v3.15.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadHIGH
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado4/20/2017
Ultima modificacion4/20/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
aveva:wonderware_intouch_access_anywhere
Debilidades (CWE)
CWE-326
Referencias
http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000114/(ics-cert@hq.dhs.gov)
http://www.securityfocus.com/bid/97256(ics-cert@hq.dhs.gov)
https://ics-cert.us-cert.gov/advisories/ICSA-17-089-01(ics-cert@hq.dhs.gov)
http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000114/(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/97256(af854a3a-2127-422b-91ae-364da2661108)
https://ics-cert.us-cert.gov/advisories/ICSA-17-089-01(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.