CVE-2017-9635 Information
Feb 14, 2021
cve
Description
Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security a weakness in the password hashing algorithm could be exploited to reverse the user’s password. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Reference
http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000118/ http://www.securityfocus.com/bid/99469 https://ics-cert.us-cert.gov/advisories/ICSA-17-187-05
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
3.9
Share on: