描述
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
AI分析AI驱动
受影响产品
schneider-electricclearscada
-
schneider-electricecostruxure_geo_scada_expert_2019
schneider-electricecostruxure_geo_scada_expert_2020
参考资料
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05PatchVendor Advisory
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0018/MNDT-2022-0018.mdThird Party Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05PatchVendor Advisory
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0018/MNDT-2022-0018.mdThird Party Advisory