QID 591084

Date Published: 2022-10-13

QID 591084: Measuresoft ScadaPro Server Vulnerability (ICSA-22-235-05)

AFFECTED PRODUCTS
The following versions of ScadaPro Server, a supervisory control and data acquisition (SCADA) system, are affected: ScadaPro Server: Versions prior to 6.8.0.1

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability may allow arbitrary code execution.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to Schneider Electric MITIGATIONS section icsa-22-235-05 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591084

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-235-05 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-235-05