SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-3940

Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

MEDIUM 6.9EPSS 0.46%

Does this matter?

Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.

Description

Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 2.0
6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS
0.46% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
schneider-electric/wonderware system platform 2014
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.