Lucene search

K
cvelistSchneiderCVELIST:CVE-2022-24319
HistoryFeb 09, 2022 - 10:05 p.m.

CVE-2022-24319

2022-02-0922:05:10
CWE-295
schneider
www.cve.org
4
improper certificate validation
man-in-the-middle attack
clearscada
ecostruxure geo scada expert

AI Score

6

Confidence

High

EPSS

0.001

Percentile

44.6%

A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)

CNA Affected

[
  {
    "product": "ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)"
      }
    ]
  }
]

AI Score

6

Confidence

High

EPSS

0.001

Percentile

44.6%

Related for CVELIST:CVE-2022-24319