QID 590722

Date Published: 2022-03-10

QID 590722: Schneider Electric EcoStruxure Geo SCADA Expert Multiple Vulnerabilities (SEVD-2022-039-05)

Affected Products and Versions
ClearSCADA all versions
EcoStruxure Geo SCADA Expert 2019, all versions
EcoStruxure Geo SCADA Expert 2020, all versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of by looking for the file "SE.Scada.ViewX" version

Successful exploitation could cause non-encrypted communication with the server when outdated versions of the ViewX client are used,could allow a Man-in-the Middle attack when communications between the client and Geo SCADA web/database server are intercepted. or Denial of Service against the Geo SCADA server when receiving a malformed HTTP request.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to advisory SEVD-2022-039-05 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590722

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2022-039-05 URL Logo www.se.com/ww/en/download/document/SEVD-2022-039-05/