Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-6854

Опубликовано: 06 янв. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vulnerability. Affected versions in current support includes ClearSCADA 2017 R3, ClearSCADA 2017 R2, and ClearSCADA 2017.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:schneider-electric:clearscada:2017:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:clearscada:2017:r2:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:clearscada:2017:r3:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00028
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287
NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

A CWE-264 Permissions, Privileges, and Access Controls vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vulnerability. Affected versions in current support includes ClearSCADA 2017 R3, ClearSCADA 2017 R2, and ClearSCADA 2017.

EPSS

Процентиль: 7%
0.00028
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-287
NVD-CWE-Other