First published: Mon Sep 25 2017(Updated: )
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Powerscada Anywhere | =1.0 | |
Schneider Electric EcoStruxure Power SCADA Expert | =8.1 | |
Schneider Electric EcoStruxure Power SCADA Expert | =8.2 | |
Schneider Electric Citect Anywhere | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7970 has been assigned a moderate severity level due to its potential to allow unauthorized specification of server target nodes.
To fix CVE-2017-7970, it is advised to update vulnerable software versions of PowerSCADA Anywhere and Citect Anywhere to the latest patched versions.
CVE-2017-7970 affects Schneider Electric's PowerSCADA Anywhere version 1.0 and Citect Anywhere version 1.0.
The impact of CVE-2017-7970 can lead to unauthorized access to server nodes, compromising the security of the system.
Yes, CVE-2017-7970 is exploitable remotely, which increases its risk profile for systems exposed to the internet.