PT-2021-15186 · Schneider Electric · Clearscada+2
Published
2021-05-26
·
Updated
2021-06-07
·
CVE-2021-22741
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ClearSCADA (all versions)
EcoStruxure Geo SCADA Expert 2019 (all versions)
EcoStruxure Geo SCADA Expert 2020 versions V83.7742.1 and prior
Description
The issue exists due to the use of password hash with insufficient computational effort, which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. It is noted that
.sde configuration export files do not contain user account password hashes.Recommendations
For ClearSCADA, consider implementing additional security measures to protect server database files.
For EcoStruxure Geo SCADA Expert 2019, restrict access to server database files to minimize the risk of exploitation.
For EcoStruxure Geo SCADA Expert 2020 versions V83.7742.1 and prior, update to a version later than V83.7742.1 to mitigate the risk.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearscada
Ecostruxure Geo Scada Expert 2019
Ecostruxure Geo Scada Expert 2020