CVE-2022-24319
5.9MEDIUMA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Pro
Publicado: 2/9/2022Actualizado: 11/21/2024
Descripción
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
Análisis IAImpulsado por IA
Productos Afectados
schneider-electricclearscada
-
schneider-electricecostruxure_geo_scada_expert_2019
schneider-electricecostruxure_geo_scada_expert_2020
Referencias
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05PatchVendor Advisory
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0018/MNDT-2022-0018.mdThird Party Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05PatchVendor Advisory
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0018/MNDT-2022-0018.mdThird Party Advisory