Schneider-Electric Clearscada vulnerabilities
2 known vulnerabilities affecting schneider-electric/clearscada.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-6854HIGHCVSS 7.8v20172020-01-06
CVE-2019-6854 [HIGH] CWE-287 CVE-2019-6854: A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Exp
A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vuln
nvd
CVE-2017-6021HIGHCVSS 7.5v2014v20152018-05-14
CVE-2017-6021 [HIGH] CWE-20 CVE-2017-6021: In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and pr
In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA
nvd