CVE-2017-7969: CSRF
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7969?
CVE-2017-7969 is classified as a critical cross-site request forgery vulnerability.
How do I fix CVE-2017-7969?
To mitigate CVE-2017-7969, users should apply the latest patches or updates provided by Schneider Electric.
What products are affected by CVE-2017-7969?
CVE-2017-7969 affects Schneider Electric's PowerSCADA Anywhere version 1.0 and Citect Anywhere version 1.0.
How does CVE-2017-7969 impact user security?
CVE-2017-7969 can lead to unauthorized actions being performed on behalf of an authenticated user, compromising security.
Can CVE-2017-7969 be exploited remotely?
Yes, CVE-2017-7969 can be exploited remotely, allowing attackers to send malicious requests without user knowledge.