CVE-2022-24319: Medium severity schneider electric clearscada vulnerability
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-24319?
CVE-2022-24319 is a vulnerability known as Improper Certificate Validation that allows for a Man-in-the-Middle attack on the client and Geo SCADA web server.
Which products are affected by CVE-2022-24319?
The affected products include ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), and EcoStruxure Geo SCADA Expert 2020.
What is the severity of CVE-2022-24319?
The severity of CVE-2022-24319 is medium (5.9).
How can a Man-in-the-Middle attack be prevented in Geo SCADA?
To prevent a Man-in-the-Middle attack in Geo SCADA, it is recommended to ensure proper certificate validation and encryption of communications.
Where can I find more information about CVE-2022-24319?
More information about CVE-2022-24319 can be found at the following references: [Reference 1](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05), [Reference 2](https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0018/MNDT-2022-0018.md).