CVE-2022-24320
09.02.2022, 23:15
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | clearscada | - |
schneider-electric | ecostruxure_geo_scada_expert_2019 | * |
schneider-electric | ecostruxure_geo_scada_expert_2020 | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References