CVE-2022-24320
5.9MEDIUMA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affecte
Publicado: 2/9/2022Atualizado: 11/21/2024
Descrição
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
Análise IADesenvolvido por IA
Produtos Afetados
schneider-electricclearscada
-
schneider-electricecostruxure_geo_scada_expert_2019
schneider-electricecostruxure_geo_scada_expert_2020
Referências
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05PatchVendor Advisory
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0019/MNDT-2022-0019.mdThird Party Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05PatchVendor Advisory
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0019/MNDT-2022-0019.mdThird Party Advisory