LiveActive security incident?Get immediate response
CVE Record

CVE-2015-6485: Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, S...

Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw affects older Schneider Electric Telvent Sage and LANDAC RTUs used in industrial environments. A remote attacker could read unintended data from device memory through Ethernet packet padding, potentially exposing sensitive operational information. The provided sources do not include CVSS scoring or evidence of active exploitation.

Executive priority

Prioritize this where affected RTUs support critical operations or are reachable beyond tightly controlled ICS networks. The issue is information disclosure, not confirmed system takeover, but exposed operational memory can still support later targeting.

Technical view

CVE-2015-6485 is an information disclosure issue in listed RTU firmware versions. Devices may leak sensitive memory contents when an attacker reads a padding field in an Ethernet packet. Affected firmware is identified for Sage 2300 before C3413-500-S01 and LANDAC II-2/Sage 1410/1430/1450/2400/3030M before C3414-500-S02J2.

Likely exposure

Exposure is most likely in industrial control networks running the named Schneider Electric Telvent Sage or LANDAC RTUs with firmware older than the versions listed in the CVE description. Internet exposure is not stated in the provided sources and should not be assumed.

Exploitation context

The sources describe remote information disclosure but provide no CVSS score, public exploit details, or KEV listing. Glexia should treat active exploitation as unconfirmed based on the provided bundle.

Researcher notes

The public bundle is thin: no CVSS vector, CWE, detailed advisory text, exploit confirmation, or environmental prerequisites are included. Analysis should stay anchored to the named device families, firmware thresholds, and remote memory disclosure behavior.

Mitigation direction

  • Inventory Schneider Electric Telvent Sage and LANDAC RTUs in operational networks.
  • Upgrade Sage 2300 firmware to C3413-500-S01 or later where applicable.
  • Upgrade listed LANDAC and Sage models to C3414-500-S02J2 or later where applicable.
  • Review Schneider Electric or CISA ICS advisory guidance before production changes.
  • Restrict RTU network access to trusted industrial management paths.

Validation and detection

  • Confirm model and firmware version for each affected RTU family.
  • Compare firmware against the vulnerable thresholds listed in CVE-2015-6485.
  • Check whether RTU Ethernet access is reachable from untrusted networks.
  • Document compensating controls where firmware updates require maintenance windows.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2015-6485 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.