First published: Sun Apr 30 2017(Updated: )
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Data Center Expert | <=7.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8371 has been rated as a high severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2017-8371, upgrade your Schneider Electric StruxureWare Data Center Expert software to version 7.4.0 or later.
The risks of CVE-2017-8371 include the exposure of passwords stored in cleartext, allowing attackers to gain unauthorized access.
CVE-2017-8371 affects users of Schneider Electric StruxureWare Data Center Expert versions prior to 7.4.0.
Exploitation of CVE-2017-8371 can occur through remote attacks that leverage cleartext password storage.