A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. Affected Products: EcoStruxure Geo SCADA Expert 2019 - 2021 (formerly known as ClearSCADA) (Versions prior to October 2022)
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-02_Geo_SCADA_Security_Notification.pdf | Mitigation Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: schneider
Published: 2023-01-31T00:00:00
Updated: 2023-02-03T00:00:00
Reserved: 2023-01-04T00:00:00
Link: CVE-2023-22611
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-01-31T17:15:08.927
Modified: 2023-02-07T19:56:57.870
Link: CVE-2023-22611
JSON object: View
Redhat Information
No data.