#VU17278 Information disclosure in Wonderware System Platform - CVE-2019-6525
Published: January 30, 2019 / Updated: May 3, 2019
Wonderware System Platform
AVEVA Software, LLC.
Description
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to Wonderware System Platform uses an ArchestrA network user account for authentication of system processes and inter-node communications. A local attacker can make use of an API to obtain the credentials for this account.