First published: Fri Apr 03 2015(Updated: )
Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Inductive Automation Ignition | =7.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0992 is rated as a medium severity vulnerability.
To fix CVE-2015-0992, upgrade Inductive Automation Ignition to a version that does not store OPC Server credentials in cleartext.
CVE-2015-0992 affects users of Inductive Automation Ignition version 7.7.2.
CVE-2015-0992 is a credential storage vulnerability that exposes sensitive information.
Yes, local users can exploit CVE-2015-0992 to access sensitive OPC Server credentials.