Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27q3-84pw-qmf2

Опубликовано: 24 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2021(All Versions prior to October 2022), ClearSCADA (All Versions)

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2021(All Versions prior to October 2022), ClearSCADA (All Versions)

EPSS

Процентиль: 26%
0.00087
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-116
CWE-117

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2021(All Versions prior to October 2022), ClearSCADA (All Versions)

CVSS3: 5.3
fstec
больше 2 лет назад

Уязвимость SCADA-систем EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2021, ClearSCADA, позволяющая нарушителю произвольно вставлять текстовые записи в файлы журнала или заполнять файлы журнала неверными данными

EPSS

Процентиль: 26%
0.00087
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-116
CWE-117