PT-2019-2665 · Schneider Electric · Citectscada+2
Publicado
2019-05-31
·
Atualizado
2020-10-02
·
CVE-2019-10981
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vijeo Citect versions 7.30 through 7.40
CitectSCADA versions 7.30 through 7.40
PowerSCADA Expert (affected versions not specified)
Description
The issue is related to insufficient protection of registration data, which may allow an attacker to gain access to user credentials. An authenticated local user may exploit this to access Citect user credentials.
Recommendations
For Vijeo Citect versions 7.30 through 7.40, consider restricting access to the system until a fix is available.
For CitectSCADA versions 7.30 through 7.40, restrict access to the system until a fix is available.
For PowerSCADA Expert, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citectscada
Powerscada Expert
Vijeo Citect