CVE-2017-7970
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection…
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Affected
- schneider-electric/powerscada anywhere · schneider-electric/citect anywhere
- Source
- cybersecurity@se.com
References
- http://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99913Third Party Advisory, VDB Entry
- https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhereIssue Tracking, Mitigation, Patch, Vendor Advisory
- http://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99913Third Party Advisory, VDB Entry
- https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhereIssue Tracking, Mitigation, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.