The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric ClearSCADA All versions
- Schneider Electric EcoStruxure Geo SCADA Expert 2019 All versions
- Schneider Electric EcoStruxure Geo SCADA Expert 2020 All versions
- Summary
- A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-the Middle attack when communications between the client and Geo SCADA database server are intercepted.
- Remediation
- The Geo SCADA Expert 2021 product includes fixes for all the above vulnerabilities and is available for download here: https://community.exchange.se.com/t5/Geo-SCADA-Knowledge-Base/Geo-SCADA-ExpertDownloads/ba-p/279115
