CVE-2017-7969 Vulnerability Details

  /     /     /  

CVE-2017-7969 Metadata Quick Info

CVE Published: 25/09/2017 | CVE Updated: 17/09/2024 | CVE Year: 2017
Source: schneider | Vendor: Schneider Electric SE | Product: PowerSCADA Anywhere
Status : PUBLISHED

CVE-2017-7969 Description

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric\'s PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Cross Site Request Forgery
Source: Schneider Electric SE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).