Schneider Electric ClearSCADA Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
Schneider Electric ClearSCADA 2010 R3.1 (build 72.4644)
Schneider Electric ClearSCADA 2010 R3 (build 72.4560)
Description:
Bugtraq id: 69840
CVE (CAN) ID: CVE-2014-5412
Schneider Electric ClearSCADA is an open software platform that can remotely manage critical architectures.
Client user accounts in ClearSCADA can read the ClearSCADA database. This default configuration is insecure for systems in the production environment and may cause sensitive system information to be leaked to users without creden.
<* Source: CERT
Link: https://ics-cert.us-cert.gov/advisories/ICSA-14-259-01
*>
Suggestion:
Vendor patch:
Schneider Electric
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabil
Http://resourcecenter.controlmicrosystems.com/display/CS/SCADA+Expert+ClearSCADA+Support
This article permanently updates the link address: