CVE-2015-3940: Path Traversal
Published Aug 4, 2015
·Updated
Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
1 affected component
Schneider-electric Wonderware System Platform 2014=r2
Remediation
Event History
Aug 4, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3940?
CVE-2015-3940 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2015-3940?
To fix CVE-2015-3940, users should apply the latest patches for Schneider Electric Wonderware System Platform, specifically the 2014 R2 Patch 01.
3
Who is affected by CVE-2015-3940?
CVE-2015-3940 affects local users of Schneider Electric Wonderware System Platform versions prior to 2014 R2 Patch 01.
4
What type of vulnerability is CVE-2015-3940?
CVE-2015-3940 is an untrusted search path vulnerability that allows exploitation via a Trojan horse DLL.
5
Can CVE-2015-3940 be exploited remotely?
No, CVE-2015-3940 requires local access to the system to exploit the vulnerability.