Improper Certificate Validation Vulnerability in ClearSCADA and EcoStruxure Geo SCADA Expert
CVE-2022-24320
5.9MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 9 February 2022
What is CVE-2022-24320?
An improper certificate validation vulnerability exists in ClearSCADA and EcoStruxure Geo SCADA Expert, which could potentially allow attackers to execute Man-in-the-Middle attacks. This vulnerability arises when the communication between the client and the Geo SCADA database server is intercepted, enabling unauthorized access and data manipulation. It is crucial for users of these systems to implement necessary mitigations to secure their environments against potential exploits.
Affected Version(s)
ClearSCADA (All ), EcoStruxure Geo SCADA Expert 2019 (All ), EcoStruxure Geo SCADA Expert 2020 (All ) ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)