PT-2023-1235 · Schneider Electric · Ecostruxure Geo Scada Expert+1

Published

2023-01-10

·

Updated

2023-02-07

·

CVE-2023-22611

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions EcoStruxure Geo SCADA Expert versions 2019 through 2021 ClearSCADA (all versions)
Description A vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. This issue is related to the lack of protection for service data, which could allow a remote attacker to disclose protected information.
Recommendations For EcoStruxure Geo SCADA Expert versions 2019 through 2021, update to a version released after October 2022. For ClearSCADA, since all versions are affected and no specific fix is mentioned, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00465
CVE-2023-22611

Affected Products

Clearscada
Ecostruxure Geo Scada Expert