CVE-2017-5158

CRITICAL

An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL para...

Affects 1 product across 1 vendor.

BCS7.93
CVSS 3.19.8
EPSS2.4%
Percentile82th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-200: Exposure of Sensitive Information

Application reveals restricted data such as system internals, credentials, or user data to unauthorized actors.

Related Attack Patterns (CAPEC)
CAPEC-13 Subverting Environment Variable Values
via CWE-200
CAPEC-59 Session Credential Falsification through Prediction
via CWE-200
CAPEC-60 Reusing Session IDs (aka Session Replay)
via CWE-200
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-200
CAPEC-285 ICMP Echo Request Ping
via CWE-200
Show all 59

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical information exposure vulnerability exists in Schneider Electric Wonderware InTouch Access Anywhere, versions 11.5.2 and prior. This flaw allows credentials to be exposed to external systems via URL parameters, posing significant risks to operational security and data confidentiality.

BSID: BS-2017-GLOBAL-119980-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2017-5158?
A critical information exposure vulnerability exists in Schneider Electric Wonderware InTouch Access Anywhere, versions 11.5.2 and prior. This flaw allows credentials to be exposed to external systems via URL parameters, posing significant risks to operational security and data confidentiality.
What is the CVSS score for CVE-2017-5158?
CVE-2017-5158 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 2.4%.
Is CVE-2017-5158 actively exploited?
No confirmed active exploitation of CVE-2017-5158 as of 2026-05-30.
How do I remediate CVE-2017-5158?
Priority: HIGH. Advisory: http://software.schneider-electric.com/pdf/security-bulletin/lfsec00000114/ PSIRT: [email protected]
What systems are affected by CVE-2017-5158?
CVE-2017-5158 affects: Aveva.
What NERC-CIP standard applies to CVE-2017-5158?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 by exposing sensitive information that could be used to compromise the security of electronic access control and monitoring systems.
What IEC 62443 requirement maps to CVE-2017-5158?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves the protection of sensitive information from being disclosed to unauthorized entities, which is crucial for maintaining the security of industrial control systems.
Vulnerability Details
CVE IDCVE-2017-5158
BSIDBS-2017-GLOBAL-119980-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2017-04-20
Last Modified2026-05-13
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely without authentication. An attacker can craft specific URL parameters to expose credentials to arbitrary destination addresses, leading to potential unauthorized access and data exfiltration.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Aveva Wonderware Intouch Access Anywhere
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 3383 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and output encoding on the affected application to prevent credential exposure via URL parameters. Additionally, monitor network traffic for suspicious activity and use web application firewalls to block malicious requests.

SURICATA RULE
alert http any any -> any any (msg:"CVE-2017-5158 - Wonderware InTouch Access Anywhere Credential Exposure"; flow:established,to_server; content:"/inTouch/"; http_uri; content:"?dest="; http_uri; sid:9100045; rev:1;)
NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 by exposing sensitive information that could be used to compromise the security of electronic access control and monitoring systems.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves the protection of sensitive information from being disclosed to unauthorized entities, which is crucial for maintaining the security of industrial control systems.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hasha5e4e2d8c720c7c0e3727cadcd59ddec1a321a98511ea9ad297a05bb910b739b2c8c39db15dc5215ce2e0ac225f629b06a09a43d232f49f585f153b666511ca7
Related CVEs affecting Aveva
CVE-2011-3143 10.0 Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, a... CVE-2025-61937 10.0 The vulnerability, if exploited, could allow an unauthenticated miscreant to... CVE-2022-1467 9.9 Windows OS can be configured to overlay a “language bar” on top of any applic... CVE-2018-10628 9.8 AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and... CVE-2018-10620 9.8 AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017...
View all Aveva CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →