Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schneider Electric
Schneider Electric wonderware Information Server Portal |
|
| CPEs | cpe:2.3:a:schneider_electric:wonderware_information_server_portal:4.0_sp1:*:*:*:*:*:*:* cpe:2.3:a:schneider_electric:wonderware_information_server_portal:4.5:*:*:*:*:*:*:* cpe:2.3:a:schneider_electric:wonderware_information_server_portal:5.0:*:*:*:*:*:*:* cpe:2.3:a:schneider_electric:wonderware_information_server_portal:5.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Schneider Electric
Schneider Electric wonderware Information Server Portal |
Fri, 31 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Schneider Electric Wonderware Input Validation | |
| References |
|
Status: PUBLISHED
Assigner: icscert
Published: 2014-08-28T01:00:00.000Z
Updated: 2025-10-31T23:16:04.348Z
Reserved: 2014-08-22T00:00:00.000Z
Link: CVE-2014-5398
No data.
Status : Deferred
Published: 2014-08-28T01:55:03.607
Modified: 2025-11-01T00:15:32.950
Link: CVE-2014-5398
No data.