Multiple Schneider Electric Products XML External Entity Information Disclosure Vulnerability
BID:61598
Info
Multiple Schneider Electric Products XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 61598 |
| Class: | Unknown |
| CVE: |
CVE-2013-2796 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 16 2013 12:00AM |
| Updated: | Mar 19 2015 08:09AM |
| Credit: | Timur Yunusov, Alexey Osipov and Ilya Karpov of Positive Technologies |
| Vulnerable: |
Schneider Electric Vijeo Citect 7.20 |
| Not Vulnerable: | |
Discussion
Multiple Schneider Electric Products XML External Entity Information Disclosure Vulnerability
Multiple Schneider Electric products are prone to an information-disclosure vulnerability.
Local attacker can leverage this issue to obtain sensitive information or cause denial-of-service condition.
The following products are affected:
Vijeo Citect 7.20 and prior
CitectSCADA 7.20 and prior
PowerLogic SCADA 7.20 and prior
Multiple Schneider Electric products are prone to an information-disclosure vulnerability.
Local attacker can leverage this issue to obtain sensitive information or cause denial-of-service condition.
The following products are affected:
Vijeo Citect 7.20 and prior
CitectSCADA 7.20 and prior
PowerLogic SCADA 7.20 and prior
Exploit / POC
Multiple Schneider Electric Products XML External Entity Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Schneider Electric Products XML External Entity Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Schneider Electric Products XML External Entity Information Disclosure Vulnerability
References:
References:
- Advisory of Vulnerability Affecting Vijeo Citect, Citect SCADA, and PowerLogic S (Schneider Electric)
- Schneider Electric Homepage (Schneider Electric)
- Vulnerability Disclosure - CitectSCADA, Vijeo Citect, PowerLogic SCADA (Schneider Electric)
- Advisory (ICSA-13-217-02) SCHNEIDER ELECTRIC VIJEO CITECT, CITECTSCADA, POWERLOG (ICS-CERT)