VulnerabilityModified
CVE-2017-8371
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.
MEDIUM 6.8EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- schneider-electric/struxureware data center expert
- Source
- cve@mitre.org
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-343-01Mitigation, Patch, Vendor Advisory
- http://www.datacenterdynamics.com/content-tracks/security-risk/schneider-patches-critical-vulnerability-in-struxureware-dcim/97738.fullarticleThird Party Advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-343-01Mitigation, Patch, Vendor Advisory
- http://www.datacenterdynamics.com/content-tracks/security-risk/schneider-patches-critical-vulnerability-in-struxureware-dcim/97738.fullarticleThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.