CVE-2014-5398: Schneider Electric Wonderware Input Validation
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5398?
CVE-2014-5398 has a medium severity rating due to its potential to allow remote attackers to read arbitrary files or cause a denial of service.
How do I fix CVE-2014-5398?
To address CVE-2014-5398, ensure you update the Wonderware Information Server to a version that is not vulnerable, ideally the latest available patch.
Which versions of Schneider Electric Wonderware Information Server are affected by CVE-2014-5398?
CVE-2014-5398 affects versions 4.0 SP1 through 5.5 of Schneider Electric Wonderware Information Server.
What can attackers do with CVE-2014-5398?
Attackers exploiting CVE-2014-5398 can read arbitrary files or execute a denial of service attack against the server.
Is configuration change required to mitigate CVE-2014-5398?
Mitigation of CVE-2014-5398 primarily involves applying updates rather than configuration changes, as it addresses vulnerabilities in the software itself.