First published: Thu Jun 22 2017(Updated: )
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Powerscada Anywhere | =1.0 | |
Schneider Electric EcoStruxure Power SCADA Expert | =8.1 | |
Schneider Electric EcoStruxure Power SCADA Expert | =8.2 | |
Schneider Electric Citect Anywhere | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7971 has a medium severity level due to the use of outdated cipher suites and improper verification of peer SSL certificates.
To fix CVE-2017-7971, update to the latest versions of Schneider Electric's PowerSCADA Anywhere and Citect Anywhere that address this vulnerability.
CVE-2017-7971 affects Schneider Electric's PowerSCADA Anywhere v1.0 and Citect Anywhere v1.0.
The potential impacts of CVE-2017-7971 include exposure to man-in-the-middle attacks due to improper SSL certificate verification.
As of now, there are no publicly known exploits specifically targeting CVE-2017-7971.