PT-2017-18037 · Schneider Electric · Powerscada Anywhere+2

Publicado

2017-09-25

·

Atualizado

2017-09-29

·

CVE-2017-7971

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Schneider Electric PowerSCADA Anywhere version 1.0 Schneider Electric PowerSCADA Expert versions 8.1 through 8.2 Citect Anywhere version 1.0
Description A security issue exists that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
Recommendations For Schneider Electric PowerSCADA Anywhere version 1.0, update the cipher suites to current standards and ensure proper verification of peer SSL Certificates. For Schneider Electric PowerSCADA Expert versions 8.1 through 8.2, update the cipher suites to current standards and ensure proper verification of peer SSL Certificates. For Citect Anywhere version 1.0, update the cipher suites to current standards and ensure proper verification of peer SSL Certificates.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7971

Produtos afetados

Citect Anywhere
Powerscada Anywhere
Powerscada Expert