TROYANOSYVIRUS
Back to CVEs

CVE-2017-5160

MEDIUM
5.3

Description

An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.

CVE Details

CVSS v3.1 Score5.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
Published4/20/2017
Last Modified4/20/2025
Sourcenvd
Honeypot Sightings0

Affected Products

aveva:wonderware_intouch_access_anywhere

Weaknesses (CWE)

CWE-326

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.