Improper Initialization Vulnerability in Interactive Graphical SCADA System Data Server by Schneider Electric
CVE-2022-24316
7.5HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 9 February 2022
Summary
An improper initialization vulnerability exists in Schneider Electric's Interactive Graphical SCADA System Data Server. This issue can lead to information exposure, allowing attackers to exploit it by sending specially crafted messages. Users of versions V15.0.0.22020 and earlier are particularly at risk. It is critical to apply available patches and updates to safeguard against potential attacks.
Affected Version(s)
Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved