CVE-2017-7970: Medium severity schneider electric powerscada anywhere vulnerability
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7970?
CVE-2017-7970 has been assigned a moderate severity level due to its potential to allow unauthorized specification of server target nodes.
How do I fix CVE-2017-7970?
To fix CVE-2017-7970, it is advised to update vulnerable software versions of PowerSCADA Anywhere and Citect Anywhere to the latest patched versions.
Which versions are affected by CVE-2017-7970?
CVE-2017-7970 affects Schneider Electric's PowerSCADA Anywhere version 1.0 and Citect Anywhere version 1.0.
What potential impact does CVE-2017-7970 have?
The impact of CVE-2017-7970 can lead to unauthorized access to server nodes, compromising the security of the system.
Is CVE-2017-7970 exploitable remotely?
Yes, CVE-2017-7970 is exploitable remotely, which increases its risk profile for systems exposed to the internet.