VulnerabilityModified
CVE-2017-7971
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer…
MEDIUM 6.5EPSS 0.78%
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- schneider-electric/powerscada anywhere · schneider-electric/citect anywhere
- Source
- cybersecurity@se.com
References
- http://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99913Third Party Advisory, VDB Entry
- https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhereIssue Tracking, Mitigation, Patch, Vendor Advisory
- http://www.schneider-electric.com/en/download/document/SEVD-2017-173-01/Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99913Third Party Advisory, VDB Entry
- https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9071-security-notification-citect-anywhereIssue Tracking, Mitigation, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.