VulnerabilityModified
CVE-2015-3940
Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
MEDIUM 6.9EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- schneider-electric/wonderware system platform 2014
- Source
- ics-cert@hq.dhs.gov
References
- http://iom.invensys.com/EN/pdfLibrary/Security_Bulletin_LFSEC00000106.pdfPatch, Vendor Advisory
- http://www.securityfocus.com/bid/75297
- http://www.securitytracker.com/id/1033179
- http://www.securitytracker.com/id/1033180
- https://ics-cert.us-cert.gov/advisories/ICSA-15-169-02Third Party Advisory, US Government Resource
- http://iom.invensys.com/EN/pdfLibrary/Security_Bulletin_LFSEC00000106.pdfPatch, Vendor Advisory
- http://www.securityfocus.com/bid/75297
- http://www.securitytracker.com/id/1033179
- http://www.securitytracker.com/id/1033180
- https://ics-cert.us-cert.gov/advisories/ICSA-15-169-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.