PT-2022-16605 · Schneider Electric · Ecostruxure Geo Scada Expert 2020+2

Cameron Stokes

·

Published

2022-02-09

·

Updated

2022-04-22

·

CVE-2022-24320

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ClearSCADA (All Versions) EcoStruxure Geo SCADA Expert 2019 (All Versions) EcoStruxure Geo SCADA Expert 2020 (All Versions)
Description A CWE-295: Improper Certificate Validation issue exists, allowing a Man-in-the-Middle attack when communications between the client and Geo SCADA database server are intercepted. This could potentially compromise the security of the data being transmitted.
Recommendations For ClearSCADA, consider implementing proper certificate validation to prevent Man-in-the-Middle attacks. For EcoStruxure Geo SCADA Expert 2019, ensure that all communications with the Geo SCADA database server are securely encrypted and validated. For EcoStruxure Geo SCADA Expert 2020, restrict access to the Geo SCADA database server to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, consider disabling the communication between the client and Geo SCADA database server until a patch is available.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24320

Affected Products

Clearscada
Ecostruxure Geo Scada Expert 2019
Ecostruxure Geo Scada Expert 2020