Vulnerability Description
Rockwell Automation RSView32 7.60.00 (aka CPR9 SR4) and earlier does not properly encrypt credentials, which allows local users to obtain sensitive information by reading a file and conducting a decryption attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Rsview32 | <= 7.60.00 |
Related Weaknesses (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-132-02Third Party AdvisoryUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/700915
- https://ics-cert.us-cert.gov/advisories/ICSA-15-132-02Third Party AdvisoryUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/700915
FAQ
What is CVE-2015-1010?
CVE-2015-1010 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Rockwell Automation RSView32 7.60.00 (aka CPR9 SR4) and earlier does not properly encrypt credentials, which allows local users to obtain sensitive information by reading a file and conducting a decry...
How severe is CVE-2015-1010?
CVE-2015-1010 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-1010?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Rsview32.