First published: Mon Feb 13 2017(Updated: )
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Invensys Wonderware Historian | =2014_r2_sp1_p01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-5155 is high due to the use of default passwords that can be exploited to compromise databases.
To fix CVE-2017-5155, ensure that all default passwords are changed to strong, unique passwords for user accounts.
CVE-2017-5155 affects Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier versions.
CVE-2017-5155 poses risks of unauthorized access and data compromise due to default password vulnerabilities.
There is no specific patch mentioned for CVE-2017-5155, but changing default passwords is essential to mitigate the vulnerability.