PT-2022-3204 · Unknown · Geo Scada Mobile

Published

2022-06-14

·

Updated

2022-07-06

·

CVE-2022-32530

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Geo SCADA Mobile versions prior to Build 223
Description A vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option, or the wrong control request when a mobile device has been compromised by a malicious application. This issue is related to insufficient boundaries within the system, potentially allowing an attacker to impact the integrity, availability, and confidentiality of protected information by launching a malicious application.
Recommendations For Geo SCADA Mobile versions prior to Build 223, update to a version newer than Build 222 to resolve the issue. As a temporary workaround, consider restricting access to the mobile device and implementing additional security measures to prevent malicious applications from compromising the device.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03895
CVE-2022-32530

Affected Products

Geo Scada Mobile