CVE-2015-0992: Infoleak
Published Apr 3, 2015
·Updated
Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.
Affected Software
1 affected component
inductiveautomation Ignition=7.7.2
Event History
Apr 3, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0992?
CVE-2015-0992 is rated as a medium severity vulnerability.
2
How do I fix CVE-2015-0992?
To fix CVE-2015-0992, upgrade Inductive Automation Ignition to a version that does not store OPC Server credentials in cleartext.
3
Who is affected by CVE-2015-0992?
CVE-2015-0992 affects users of Inductive Automation Ignition version 7.7.2.
4
What type of vulnerability is CVE-2015-0992?
CVE-2015-0992 is a credential storage vulnerability that exposes sensitive information.
5
Can local users exploit CVE-2015-0992?
Yes, local users can exploit CVE-2015-0992 to access sensitive OPC Server credentials.