PT-2023-1235 · Schneider Electric · Ecostruxure Geo Scada Expert+1
Published
2023-01-10
·
Updated
2023-02-07
·
CVE-2023-22611
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EcoStruxure Geo SCADA Expert versions 2019 through 2021
ClearSCADA (all versions)
Description
A vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. This issue is related to the lack of protection for service data, which could allow a remote attacker to disclose protected information.
Recommendations
For EcoStruxure Geo SCADA Expert versions 2019 through 2021, update to a version released after October 2022.
For ClearSCADA, since all versions are affected and no specific fix is mentioned, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearscada
Ecostruxure Geo Scada Expert