EcoStruxure Geo SCADA Expert and ClearSCADA Log Injection Vulnerability Notification
This document details a medium-severity vulnerability (CVE-2023-0595) in Schneider Electric's EcoStruxure Geo SCADA Expert and ClearSCADA products, where improper output neutralization for logs (CWE-117) allows attackers to inject arbitrary text entries into log files via the database web port. The notification provides remediation through October 2022 updates and recommends mitigations such as restricting network access to the affected port.
Failed to load PDF
Download insteadYou might also like
WilcoROWCO Metal Clad Industrial Switchgear Catalogue
5 pages
MZ20B Electro-Mechanical Actuator Specifications and Installation Guide
3 pages
Redundant Group Control Application Note
8 pages
Satchwell AL Series Linear Actuator Data Sheet
8 pages
Acti9 iID B Type RCCB for Residential EV Charging Stations Solution Guide
2 pages
EcoStruxure Reference Design 47 Modular Data Center for AI Clusters
10 pages
DEGW-Steel Electronic Immersion Temperature Transmitter Technical Data
2 pages
SPW 100 Series Wet Differential Pressure Transmitter Datasheet
2 pages
TAC Xenta 400 Programmable Controller Manual
3 pages
194 Series Panel Mount Socket with Tab Terminals Datasheet
1 pages