{ "id": "CVE-2023-0595", "sourceIdentifier": "cybersecurity@se.com", "published": "2023-02-24T11:15:10.643", "lastModified": "2024-11-21T07:37:27.610", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2021(All Versions prior to October 2022), ClearSCADA (All Versions)\n\n" } ], "metrics": { "cvssMetricV31": [ { "source": "cybersecurity@se.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" }, "exploitabilityScore": 3.9, "impactScore": 1.4 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE" }, "exploitabilityScore": 3.9, "impactScore": 1.4 } ] }, "weaknesses": [ { "source": "cybersecurity@se.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-117" } ] }, { "source": "nvd@nist.gov", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-116" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:clearscada:*:*:*:*:*:*:*:*", "matchCriteriaId": "8117E9AF-97C7-4C10-BE59-5341D32667F4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:-:*:*:*:*:*:*:*", "matchCriteriaId": "32C7EA19-134A-4FF8-BB49-133020612947" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7268.1:*:*:*:*:*:*:*", "matchCriteriaId": "337B3FD9-3C56-4914-B876-85928A4269DE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7322.1:*:*:*:*:*:*:*", "matchCriteriaId": "599591CD-340D-4F5C-9442-3B77138DE5EE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7429.2:*:*:*:*:*:*:*", "matchCriteriaId": "0E1CB9D8-07C9-492D-A4C5-87D5AAE73538" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7457.1:*:*:*:*:*:*:*", "matchCriteriaId": "07CCE0CE-7ABC-4B32-8071-35C62F51184C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7488.1:*:*:*:*:*:*:*", "matchCriteriaId": "4EE0670A-636C-48DB-83CB-5CAB29EDB399" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7522.1:*:*:*:*:*:*:*", "matchCriteriaId": "496D8DD9-00A0-4F06-B2BA-A51A0178C29D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7545.1:*:*:*:*:*:*:*", "matchCriteriaId": "66924EF0-0776-45A3-A61E-2EB1DEDEF391" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7578.1:*:*:*:*:*:*:*", "matchCriteriaId": "DB87BE8B-CA3E-4D64-BA78-DD0E86DFCA88" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7613.1:*:*:*:*:*:*:*", "matchCriteriaId": "42883228-4736-4148-B7AD-08FD829FC07C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7641.1:*:*:*:*:*:*:*", "matchCriteriaId": "3BE6E43F-B4C1-47F5-994C-3154D47D728E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7690.1:*:*:*:*:*:*:*", "matchCriteriaId": "711E747D-7DF5-4576-AA01-E9B1B884F829" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7714.1:*:*:*:*:*:*:*", "matchCriteriaId": "68D619A4-0F05-4C67-848B-E862954AB767" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7742.1:*:*:*:*:*:*:*", "matchCriteriaId": "6D3AE4FA-D915-4F2C-8958-54DCC5118CC8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7777.1:*:*:*:*:*:*:*", "matchCriteriaId": "0FA71158-C61D-4F94-AA44-5C881601F18C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7808.2:*:*:*:*:*:*:*", "matchCriteriaId": "C52F5ACB-5811-4BE2-988A-B922E8848801" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7840.1:*:*:*:*:*:*:*", "matchCriteriaId": "8C36FAD5-E91F-4F54-ABBF-907EF2561D21" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7875.1:*:*:*:*:*:*:*", "matchCriteriaId": "9A16BFCC-22ED-4D6E-9737-29E33B9870BF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7896.1:*:*:*:*:*:*:*", "matchCriteriaId": "858A14E9-9FFA-47F2-ACC3-5A0A1B5754A0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7936.1:*:*:*:*:*:*:*", "matchCriteriaId": "B7F71EB4-CAE9-430B-929A-A5B4B1D0BDEB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.7980.1:*:*:*:*:*:*:*", "matchCriteriaId": "167317B6-BFC2-4DB8-AC22-F8C5E2BCEFA1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8015.1:*:*:*:*:*:*:*", "matchCriteriaId": "31B0EC77-A143-4919-BBF5-95127999FF7C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8108.2:*:*:*:*:*:*:*", "matchCriteriaId": "6C717C22-CA76-4FC4-8565-F81C614A27F2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8122.1:*:*:*:*:*:*:*", "matchCriteriaId": "337BA43E-CACF-4806-B641-35E1425A7C65" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8155.1:*:*:*:*:*:*:*", "matchCriteriaId": "71905992-FD0E-4FDA-A0A4-0C26BE5F8DE1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8172.1:*:*:*:*:*:*:*", "matchCriteriaId": "4F9491C1-24B7-4AB2-8405-DE8B308537CD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8197.1:*:*:*:*:*:*:*", "matchCriteriaId": "71862239-5155-4971-9E40-4444A7711148" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8220.1:*:*:*:*:*:*:*", "matchCriteriaId": "E81E4F51-1258-4AB6-B95A-CC787EDF0BB4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:81.8267.1:*:*:*:*:*:*:*", "matchCriteriaId": "FD44BC64-F34B-4682-9EB1-0538D28D39FD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:-:*:*:*:*:*:*:*", "matchCriteriaId": "A5AA4D7F-76AA-45A7-86C9-4C57D5C23D8D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7551.1:*:*:*:*:*:*:*", "matchCriteriaId": "51BA5080-1791-4406-AFC3-807C9931E8F6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7578.1:*:*:*:*:*:*:*", "matchCriteriaId": "DD4B1884-110F-4D2B-A671-F9CDCCC0055A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7613.1:*:*:*:*:*:*:*", "matchCriteriaId": "7EEDA987-6E1F-4D3D-B65B-90B8EA59A4EA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7641.1:*:*:*:*:*:*:*", "matchCriteriaId": "FAF6A930-242F-4479-A504-9E5BC0A4B0AC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7692.1:*:*:*:*:*:*:*", "matchCriteriaId": "3B5D2147-D8E9-4A45-A1A3-C4376C18DEDC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7717.1:*:*:*:*:*:*:*", "matchCriteriaId": "F122BED3-BC5C-41A6-9785-E10E1E0DCA20" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7742.1:*:*:*:*:*:*:*", "matchCriteriaId": "E6A9061F-D17A-45CC-BC8E-75A35E5919A8" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7787.1:*:*:*:*:*:*:*", "matchCriteriaId": "C0E703DE-39EC-4055-B0D0-729BFD4E4126" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7809.1:*:*:*:*:*:*:*", "matchCriteriaId": "294CBA2E-6004-4546-8BE2-44197A6FDC84" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7840.1:*:*:*:*:*:*:*", "matchCriteriaId": "A0123B7C-3FB6-47CC-94D8-595BC6514419" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7875.1:*:*:*:*:*:*:*", "matchCriteriaId": "ECAB0301-6040-4C8D-AF70-87FCDD423DCB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7913.1:*:*:*:*:*:*:*", "matchCriteriaId": "E52B3825-334A-4C4B-9186-FDF7B46127A4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7936.2:*:*:*:*:*:*:*", "matchCriteriaId": "8F400AFD-2CDD-4DD7-8276-8CAC66924E11" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.7980.2:*:*:*:*:*:*:*", "matchCriteriaId": "AB3C4797-9995-472B-9607-18ED9C76C73B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8017.1:*:*:*:*:*:*:*", "matchCriteriaId": "A923C3EE-44D0-4143-838E-608BC8B96E03" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8108.1:*:*:*:*:*:*:*", "matchCriteriaId": "ED6BEE89-D04B-46A4-BFF6-B34CC577E38D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8122.2:*:*:*:*:*:*:*", "matchCriteriaId": "504D36B5-2AAB-4B8C-ADA6-A2B23C25A7E3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8155.1:*:*:*:*:*:*:*", "matchCriteriaId": "FE6C0472-CF2A-4C92-A75D-1FEFCD375E33" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8181.1:*:*:*:*:*:*:*", "matchCriteriaId": "B10159C3-98C4-4A13-B513-6012C3AC9B35" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8197.1:*:*:*:*:*:*:*", "matchCriteriaId": "42B3C6B3-EB4C-4B81-8914-EA2CCB5E0D24" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8221.1:*:*:*:*:*:*:*", "matchCriteriaId": "6E25CAE4-84AB-4161-9C91-9ACF541AB65B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:83.8267.1:*:*:*:*:*:*:*", "matchCriteriaId": "31EF8CD9-10F5-490A-A070-76DCA6757AC9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:-:*:*:*:*:*:*:*", "matchCriteriaId": "2C26D6FD-4A8A-4C35-9AFD-1CF44345832A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8027.1:*:*:*:*:*:*:*", "matchCriteriaId": "D373AAB2-CBF0-4051-BCEF-CFF88E65FA37" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8108.1:*:*:*:*:*:*:*", "matchCriteriaId": "FDACB10C-9DC1-458A-A177-49D3CD86E3B5" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8120.1:*:*:*:*:*:*:*", "matchCriteriaId": "75FFE1B0-7C58-4E64-B429-E6354E00DD43" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8158.1:*:*:*:*:*:*:*", "matchCriteriaId": "2F2FE473-2BDC-4FD2-A55D-B5D35E35653C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8182.1:*:*:*:*:*:*:*", "matchCriteriaId": "C447E85B-ADF3-4948-B622-03C2656A9E9A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8197.1:*:*:*:*:*:*:*", "matchCriteriaId": "FBBE34D7-C746-4C37-BD75-124D77588AF7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8218.1:*:*:*:*:*:*:*", "matchCriteriaId": "753F662D-A172-459B-B3C9-D419C6559858" }, { "vulnerable": true, "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2021:84.8269.1:*:*:*:*:*:*:*", "matchCriteriaId": "8FB1525E-726C-4E78-8F74-378956B33F54" } ] } ] } ], "references": [ { "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-045-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-045-01.pdf", "source": "cybersecurity@se.com" }, { "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-045-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-045-01.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }