StruxureWare SCADA Expert ClearSCADA Weak Hashing Algorithm

Medium Nessus Plugin ID 81049


The remote device is using a weak hashing algorithm.


The self-signed certificate is signed with MD5, a depreciated and weak signing algorithm. An attacker can decrypt and decipher keys hashed with this algorithm.


Asset owners should obtain a signed web certificate from a certificate authority.

See Also

Plugin Details

Severity: Medium

ID: 81049

File Name: scada_clearscada_weak_hashing_algorithm.nbin

Version: $Revision: 1.20 $

Type: remote

Family: SCADA

Published: 2015/01/28

Modified: 2018/01/29

Dependencies: 57571, 56984

Risk Information

Risk Factor: Medium


Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:schneider-electric:clearscada, cpe:/a:schneider-electric:scada_expert_clearscada

Required KB Items: SSL/Chain/WeakHash, SSL/Supported

Patch Publication Date: 2014/10/06

Vulnerability Publication Date: 2014/08/29

Reference Information

CVE: CVE-2014-5413

BID: 69842

OSVDB: 111240

ICSA: 14-259-01A