Improper Certificate Validation Vulnerability in ClearSCADA and EcoStruxure Geo SCADA Expert
CVE-2022-24320
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 9 February 2022
Summary
An improper certificate validation vulnerability exists in ClearSCADA and EcoStruxure Geo SCADA Expert, which could potentially allow attackers to execute Man-in-the-Middle attacks. This vulnerability arises when the communication between the client and the Geo SCADA database server is intercepted, enabling unauthorized access and data manipulation. It is crucial for users of these systems to implement necessary mitigations to secure their environments against potential exploits.
Affected Version(s)
ClearSCADA (All ), EcoStruxure Geo SCADA Expert 2019 (All ), EcoStruxure Geo SCADA Expert 2020 (All ) ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved