CVE-2022-24318: Weak Encryption
A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24318?
The severity of CVE-2022-24318 is high with a CVSS score of 7.5.
Which products are affected by CVE-2022-24318?
ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), and EcoStruxure Geo SCADA Expert 2020 are affected by CVE-2022-24318.
What is the description of CVE-2022-24318?
CVE-2022-24318 is a CWE-326 Inadequate Encryption Strength vulnerability that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used.
How can I fix CVE-2022-24318?
To fix CVE-2022-24318, it is recommended to update to the latest version of the affected products provided by Schneider Electric.
Where can I find more information about CVE-2022-24318?
More information about CVE-2022-24318 can be found at the following reference: [CVE-2022-24318](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05).