PT-2022-3204 · Unknown · Geo Scada Mobile
Published
2022-06-14
·
Updated
2022-07-06
·
CVE-2022-32530
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Geo SCADA Mobile versions prior to Build 223
Description
A vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option, or the wrong control request when a mobile device has been compromised by a malicious application. This issue is related to insufficient boundaries within the system, potentially allowing an attacker to impact the integrity, availability, and confidentiality of protected information by launching a malicious application.
Recommendations
For Geo SCADA Mobile versions prior to Build 223, update to a version newer than Build 222 to resolve the issue. As a temporary workaround, consider restricting access to the mobile device and implementing additional security measures to prevent malicious applications from compromising the device.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geo Scada Mobile