Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2018-05-18T13:00:00Z
Updated: 2024-09-17T00:46:48.642Z
Reserved: 2017-06-14T00:00:00
Link: CVE-2017-9637
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-05-18T13:29:00.283
Modified: 2024-11-21T03:36:33.920
Link: CVE-2017-9637
Redhat
No data.