8% (76) 1.2k views 4 pages

EcoStruxure Geo SCADA Expert and ClearSCADA Log Injection Vulnerability Notification

AI-enhanced description

This document details a medium-severity vulnerability (CVE-2023-0595) in Schneider Electric's EcoStruxure Geo SCADA Expert and ClearSCADA products, where improper output neutralization for logs (CWE-117) allows attackers to inject arbitrary text entries into log files via the database web port. The notification provides remediation through October 2022 updates and recommends mitigations such as restricting network access to the affected port.

Uploaded by LUKA.MILAN
Download
/ 4
Loading document…