Loading
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.
Use CWE-200, Indusoft vendor hub and Web Studio product page to widen CVE-2015-1009 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-0780, CVE-2011-4051 and CVE-2011-0342 for nearby disclosures in the same product family.