A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05 | patch vendor advisory |
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0019/MNDT-2022-0019.md | third party advisory |