PT-2017-18037 · Schneider Electric · Powerscada Anywhere+2

Published

2017-09-25

·

Updated

2017-09-29

·

CVE-2017-7971

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Schneider Electric PowerSCADA Anywhere version 1.0 Schneider Electric PowerSCADA Expert versions 8.1 through 8.2 Citect Anywhere version 1.0
Description A security issue exists that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
Recommendations For Schneider Electric PowerSCADA Anywhere version 1.0, update the cipher suites to current standards and ensure proper verification of peer SSL Certificates. For Schneider Electric PowerSCADA Expert versions 8.1 through 8.2, update the cipher suites to current standards and ensure proper verification of peer SSL Certificates. For Citect Anywhere version 1.0, update the cipher suites to current standards and ensure proper verification of peer SSL Certificates.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7971

Affected Products

Citect Anywhere
Powerscada Anywhere
Powerscada Expert