Unencrypted Client-Server Data Stream in Schneider Electric StruxureWare Building Expert MPM before 2.15
CVE-2015-3962 · MEDIUM Severity
AV:N/AC:L/AU:N/C:P/I:N/A:N
Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.
Learn more about our Cis Benchmark Audit For Server Software.