CVE Database
/

CVE-2014-5398

Back to search

CVE-2014-5398

Published: Aug 28, 2014

Modified: Oct 31, 2025

PUBLISHED

Description

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

VendorProductVersions

Schneider Electric

Wonderware Information Server Portal

affected
4.0 SP1
affected
4.5
affected
5.0
affected
5.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now