CVE-2017-7969
published 2017-09-26CVE-2017-7969: A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with…
PriorityP336high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.63%
45.9th percentile
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | citect_anywhere | — | — |
| schneider-electric | powerscada_anywhere | — | — |
| schneider_electric_se | citect_anywhere | — | — |
| schneider_electric_se | powerscada_anywhere | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gm35-5x3x-4xw9: A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1
ghsa_unreviewed·2022-05-17
CVE-2017-7969 [HIGH] CWE-352 GHSA-gm35-5x3x-4xw9: A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.
CISA ICS
Schneider Electric PowerSCADA Anywhere and Citect Anywhere
cisa_ics·2017-07-20
Schneider Electric PowerSCADA Anywhere and Citect Anywhere
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric PowerSCADA Anywhere and Citect Anywhere
Last RevisedJuly 20, 2017
Alert CodeICSA-17-201-01
## CVSS v3 8.1
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Schneider Electric
Equipment: PowerSCADA Anywhere and Citect Anywhere
Vulnerabilities: Information Exposure, Cross-Site Request Forgery, Improper Neutralization of Expression, Improper Validation of Certificate Expiration
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerabilities affect the following versions of PowerSCADA Anywhere and Citect Anywhere mobile extensions:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/http://www.securityfocus.com/bid/99913https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywherehttp://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/http://www.securityfocus.com/bid/99913https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhere
2017-09-26
Published