CVE-2017-5160: Weak Encryption
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5160?
CVE-2017-5160 has a medium severity rating due to its inadequate encryption strength.
How do I fix CVE-2017-5160?
To fix CVE-2017-5160, upgrade to a newer version of Schneider Electric Wonderware InTouch Access Anywhere that ensures proper SSL certificate verification.
What vulnerabilities are associated with CVE-2017-5160?
CVE-2017-5160 is associated with vulnerabilities related to insecure SSL/TLS implementations.
Which versions are affected by CVE-2017-5160?
CVE-2017-5160 affects Schneider Electric Wonderware InTouch Access Anywhere versions 11.5.2 and prior.
What type of issue is CVE-2017-5160 classified as?
CVE-2017-5160 is classified as an Inadequate Encryption Strength issue.