Vulnerability Details CVE-2015-6485
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.2%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2015-6485
-
cpe:2.3:h:schneider-electric:sage_1410:-
-
cpe:2.3:h:schneider-electric:sage_1430:-
-
cpe:2.3:h:schneider-electric:sage_1450:-
-
cpe:2.3:h:schneider-electric:sage_2300:-
-
cpe:2.3:h:schneider-electric:sage_2400:-
-
cpe:2.3:h:schneider-electric:sage_3030m:-
-
cpe:2.3:h:schneider-electric:sage_landac_ii-2:-
-
cpe:2.3:o:schneider-electric:telvent_rtu_firmware:c3413-500-001d3
-
cpe:2.3:o:schneider-electric:telvent_rtu_firmware:c3414-500-s02j1