CVE-2017-7971: Medium severity Schneider-electric Powerscada Anywhere vulnerability
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7971?
CVE-2017-7971 has a medium severity level due to the use of outdated cipher suites and improper verification of peer SSL certificates.
How do I fix CVE-2017-7971?
To fix CVE-2017-7971, update to the latest versions of Schneider Electric's PowerSCADA Anywhere and Citect Anywhere that address this vulnerability.
What products are affected by CVE-2017-7971?
CVE-2017-7971 affects Schneider Electric's PowerSCADA Anywhere v1.0 and Citect Anywhere v1.0.
What are the potential impacts of CVE-2017-7971?
The potential impacts of CVE-2017-7971 include exposure to man-in-the-middle attacks due to improper SSL certificate verification.
Is there a known exploit for CVE-2017-7971?
As of now, there are no publicly known exploits specifically targeting CVE-2017-7971.