CVE-2015-6485: Infoleak
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6485?
CVE-2015-6485 has been classified with a medium severity due to its potential for remote information disclosure.
How do I fix CVE-2015-6485?
To fix CVE-2015-6485, update the firmware of the affected Schneider Electric Telvent Sage RTUs to the latest version C3413-500-S01 or C3414-500-S02J2.
Which devices are affected by CVE-2015-6485?
CVE-2015-6485 affects Schneider Electric Telvent Sage 2300 RTUs with firmware prior to C3413-500-S01 and several other Sage RTUs with older firmware.
Can CVE-2015-6485 lead to data breaches?
Yes, CVE-2015-6485 can allow remote attackers to access sensitive information from device memory, potentially leading to data breaches.
Is there a workaround for CVE-2015-6485 if I cannot update?
Currently, there are no documented workarounds for CVE-2015-6485 other than applying the recommended firmware updates.