EcoStruxure Geo SCADA Expert and ClearSCADA Log Injection Vulnerability Notification
This document details a medium-severity vulnerability (CVE-2023-0595) in Schneider Electric's EcoStruxure Geo SCADA Expert and ClearSCADA products, where improper output neutralization for logs (CWE-117) allows attackers to inject arbitrary text entries into log files via the database web port. The notification provides remediation through October 2022 updates and recommends mitigations such as restricting network access to the affected port.
Failed to load PDF
Download insteadYou might also like
ION Enterprise and PowerLogic SCADA Software Solution
1 pages
Trihal Cast Resin Distribution Transformer Technical Specifications
2 pages
AP7951 Switched Rack PDU Specifications
2 pages
Satchwell AF Keyboard 700 COE Enthalpy Selector Installation Guide
4 pages
Geo SCADA Expert 2019 Release Notes
48 pages
AP7802J Metered Rack PDU Specifications
2 pages
Schneider Electric Electrical Distribution and Building Solutions Catalog
36 pages
MasterPacT MTZ and DA EcoFit Life Extension Services Brochure
2 pages
Acti 9 DC Circuit Breaker Selection and Configuration Guide for IT Systems
4 pages
SX-DIN-12 DIN Rail Enclosure Technical Specifications
4 pages