VulnerabilityModified
CVE-2017-9969
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior.
MEDIUM 6.7EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.
- CVSS 3.0
- 6.7 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- schneider-electric/igss mobile
- Source
- cybersecurity@se.com
References
- http://www.securityfocus.com/bid/103046Third Party Advisory, VDB Entry, Vendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-046-03Third Party Advisory, US Government Resource
- https://www.schneider-electric.com/en/download/document/SEVD-2018-039-02/Vendor Advisory
- http://www.securityfocus.com/bid/103046Third Party Advisory, VDB Entry, Vendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-046-03Third Party Advisory, US Government Resource
- https://www.schneider-electric.com/en/download/document/SEVD-2018-039-02/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.