The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure Geo SCADA Expert 2019 version 81.8267.1 and prior
- Schneider Electric EcoStruxure Geo SCADA Expert 2020 version 83.8267.1 and prior
- Schneider Electric EcoStruxure Geo SCADA Expert 2021 version 84.8269.1 and prior
- Schneider Electric ClearSCADA All Versions
- Summary
- A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port.
- Remediation
- The October 2022 Updates of EcoStruxure Geo SCADA Expert include fixes for these vulnerabilities and are available for download here: https://community.se.com/t5/Geo-SCADA-Knowledge-Base/Geo-SCADA-Expert-Downloads/ba-p/279115 Installation of new server software will require a system restart or changeover of redundant servers. Consult the Release Notes and Exchange Knowledge Base (Resource Center) for advice on the procedure: https://community.exchange.se.com/t5/Geo-SCADA-Knowledge-Base/Resource-Center-Home/ba-p/279133 The documentation also states how to verify the installed version.
