Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Schneider Electric Wonderware Input Validation | |
| References |
|
Status: PUBLISHED
Assigner: icscert
Published: 2014-08-28T01:00:00
Updated: 2025-10-31T23:16:04.348Z
Reserved: 2014-08-22T00:00:00
Link: CVE-2014-5398
No data.
Status : Deferred
Published: 2014-08-28T01:55:03.607
Modified: 2025-11-01T00:15:32.950
Link: CVE-2014-5398
No data.