CVE-2017-7971
published 2017-09-26CVE-2017-7971: A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect…
PriorityP429medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
0.78%
51.9th percentile
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | citect_anywhere | — | — |
| schneider-electric | powerscada_anywhere | — | — |
| schneider_electric_se | citect_anywhere | — | — |
| schneider_electric_se | powerscada_anywhere | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8f23-48gc-8rgj: A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1
ghsa_unreviewed·2022-05-17
CVE-2017-7971 [MEDIUM] CWE-295 GHSA-8f23-48gc-8rgj: A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
CISA ICS
Schneider Electric PowerSCADA Anywhere and Citect Anywhere
cisa_ics·2017-07-20
Schneider Electric PowerSCADA Anywhere and Citect Anywhere
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric PowerSCADA Anywhere and Citect Anywhere
Last RevisedJuly 20, 2017
Alert CodeICSA-17-201-01
## CVSS v3 8.1
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Schneider Electric
Equipment: PowerSCADA Anywhere and Citect Anywhere
Vulnerabilities: Information Exposure, Cross-Site Request Forgery, Improper Neutralization of Expression, Improper Validation of Certificate Expiration
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerabilities affect the following versions of PowerSCADA Anywhere and Citect Anywhere mobile extensions:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/http://www.securityfocus.com/bid/99913https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywherehttp://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/http://www.securityfocus.com/bid/99913https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhere
2017-09-26
Published