Improper Log Output Neutralization Vulnerability in EcoStruxure Geo SCADA by Schneider Electric
CVE-2023-0595
5.3MEDIUM
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 24 February 2023
What is CVE-2023-0595?
A vulnerability exists in EcoStruxure Geo SCADA and ClearSCADA products that allows improper output neutralization for log files. This flaw could enable the misinterpretation of log entries due to the processing of malicious packets sent to the database web port, typically at port 443. Exploitation of this vulnerability could result in significant security risks, as it may allow unauthorized access or manipulation of the log contents, impacting operational integrity and confidentiality.
Affected Version(s)
ClearSCADA All Versions
EcoStruxure Geo SCADA Expert 2019 All
EcoStruxure Geo SCADA Expert 2020 All