CVE-2017-9969
Summary
| CVE | CVE-2017-9969 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-12 23:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Igss Mobile | All | All | All | All |
| Application | Schneider-electric | Igss Mobile | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Schneider Electric IGSS Mobile CVE-2017-9969 Local Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry, Vendor Advisory |
| Security Notification- IGSS Mobile | Download Schneider Electric | CONFIRM | www.schneider-electric.com | Vendor Advisory |
| Schneider Electric IGSS Mobile | CISA | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.