PT-2021-15186 · Schneider Electric · Clearscada+2

Published

2021-05-26

·

Updated

2021-06-07

·

CVE-2021-22741

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClearSCADA (all versions) EcoStruxure Geo SCADA Expert 2019 (all versions) EcoStruxure Geo SCADA Expert 2020 versions V83.7742.1 and prior
Description The issue exists due to the use of password hash with insufficient computational effort, which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. It is noted that .sde configuration export files do not contain user account password hashes.
Recommendations For ClearSCADA, consider implementing additional security measures to protect server database files. For EcoStruxure Geo SCADA Expert 2019, restrict access to server database files to minimize the risk of exploitation. For EcoStruxure Geo SCADA Expert 2020 versions V83.7742.1 and prior, update to a version later than V83.7742.1 to mitigate the risk.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22741

Affected Products

Clearscada
Ecostruxure Geo Scada Expert 2019
Ecostruxure Geo Scada Expert 2020