Insufficiently Protected Credentials Vulnerability in EcoStruxure Geo SCADA Expert by Schneider Electric
CVE-2020-28219
Summary
A vulnerability in EcoStruxure Geo SCADA Expert allows for the potential exposure of sensitive credentials to users on the server side when web users are logged into Virtual ViewX. This risk primarily arises due to inadequate protection mechanisms for credentials, permitting unauthorized access under certain conditions. The affected versions include EcoStruxure Geo SCADA Expert 2019 up to September 2020 and EcoStruxure Geo SCADA Expert 2020 up to the same date.
Affected Version(s)
EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1) EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved