02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: icscertSchneider Electric Wonderware SQL Injection
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 1.59% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 73.4% of scored records. A rank, not a probability.
- NVD base score
- The NVD has published no score for this record
- NVD CVSS vector
- No NVD score to derive
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.2
- Published
- 2014-08-28 01:00Z12 YR AGO
- Last updated
- 2025-10-31 23:17Z10 MO AGO
- Reserved
- 2014-08-22
- Assigning CNA
- icscert
- Record state
- PUBLISHED
- Severity
- Not rated by the issuing CNA
- CNA CVSS vector
- Not published by the issuing CNA
- Weaknesses
- CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')Base
- Data version
- 5.2
- Document digest
- c639441d2b9620bfca953213700947a9f0cd85cbef2a57c63697b69abede7fbe
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
SRC: CNA
Schneider Electric has created an update for WIS web pages and
components to address the vulnerabilities listed in this advisory.
Customers using all versions of WIS are affected and should upgrade to
WIS Version 5.5 and then apply the security update.
Customers using the affected versions of WIS should set the security
level settings in the Internet browser to “Medium – High” to minimize
the risks presented by these vulnerabilities. In addition, the
Wonderware Information Server Portal can be configured to use HTTPS that
will require additional steps as documented in the products user
documentation.
Schneider Electric has released a security bulletin titled “Multiple
Vulnerabilities in Wonderware Information Server LFSEC00000102” to
announce the security update, which is available at the following
location:
https://gcsresource.invensys.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000102.pdf