Cross-Site Request Forgery in Schneider Electric's PowerSCADA Products
CVE-2017-7969
8.8HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 26 September 2017
What is CVE-2017-7969?
A cross-site request forgery vulnerability has been identified in Schneider Electric's Secure Gateway component within PowerSCADA Anywhere and its associated PowerSCADA Expert versions. This flaw allows an attacker to perform state-changing actions on behalf of a legitimate user by exploiting social engineering tactics to lure the target into clicking a malicious link. Ensuring that users are aware of this risk is critical for maintaining system integrity and protecting sensitive data.
Affected Version(s)
Citect Anywhere version 1.0
PowerSCADA Anywhere Version 1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2