PT-2022-16603 · Schneider Electric · Ecostruxure Geo Scada Expert 2020+2
Cameron Stokes
·
Published
2022-02-09
·
Updated
2022-04-22
·
CVE-2022-24319
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ClearSCADA (All Versions)
EcoStruxure Geo SCADA Expert 2019 (All Versions)
EcoStruxure Geo SCADA Expert 2020 (All Versions)
Description
A CWE-295: Improper Certificate Validation issue exists, allowing a Man-in-the-Middle attack when communications between the client and Geo SCADA web server are intercepted. This could potentially compromise the security of the data being transmitted.
Recommendations
For ClearSCADA, consider implementing proper certificate validation to prevent Man-in-the-Middle attacks.
For EcoStruxure Geo SCADA Expert 2019, ensure that all communications with the Geo SCADA web server are securely encrypted and validated.
For EcoStruxure Geo SCADA Expert 2020, restrict access to the Geo SCADA web server until a proper certificate validation mechanism is in place.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearscada
Ecostruxure Geo Scada Expert 2019
Ecostruxure Geo Scada Expert 2020