CVE-2015-3962: Schneider Electric Struxureware Building Expert Multi-Purpose Management

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.

Affected products

  • Schneider Electric Struxureware Building Expert Multi-Purpose Management: before 2.15 (fixed in 2.15)

Published 2015-09-18. Last modified 2026-06-17.