Improper Certificate Validation in Geo SCADA Web Server by Schneider Electric
CVE-2022-24319
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 9 February 2022
Summary
The vulnerability stems from improper certificate validation mechanisms in the Geo SCADA web server, allowing the possibility of Man-in-the-Middle attacks. This issue arises when the communications between the client and the web server can be intercepted, potentially enabling attackers to spoof the server's identity. It affects multiple versions of ClearSCADA and EcoStruxure Geo SCADA Expert, making it crucial for users to apply necessary security measures to mitigate associated risks.
Affected Version(s)
ClearSCADA (All ), EcoStruxure Geo SCADA Expert 2019 (All ), EcoStruxure Geo SCADA Expert 2020 (All ) ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved