CVE-2022-24320: Medium severity schneider electric clearscada vulnerability
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-24320.
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-295.
What is the severity rating of CVE-2022-24320?
CVE-2022-24320 has a severity rating of 5.9 (medium).
Which products are affected by this vulnerability?
This vulnerability affects ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), and EcoStruxure Geo SCADA Expert 2020.
How can a Man-in-the-Middle attack be prevented in this case?
To prevent a Man-in-the-Middle attack in this case, it is recommended to ensure proper certificate validation is implemented for communications between the client and Geo SCADA database server.