LOW · 2.1

CVE-2014-5398

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in...

Vulnerability Description

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
InvensysWonderware Information Server4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-5398?

CVE-2014-5398 is a vulnerability with a CVSS score of 2.1 (LOW). Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in...

How severe is CVE-2014-5398?

CVE-2014-5398 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-5398?

Check the references section above for vendor advisories and patch information. Affected products include: Invensys Wonderware Information Server.