CVE-2015-3962 Information

Description

Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream which allows remote attackers to discover credentials by sniffing the network.

Reference

http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-254-01 https://ics-cert.us-cert.gov/advisories/ICSA-15-258-01

Share on: