Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-22741


Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. Note that “.sde” configuration export files do not contain user account password hashes.


Published

2021-05-26T20:15:09.253

Last Modified

2024-11-21T05:50:34.430

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-916

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application schneider-electric clearscada * Yes
Application schneider-electric ecostruxure_geo_scada_expert_2019 * Yes
Application schneider-electric ecostruxure_geo_scada_expert_2020 ≤ 83.7742.1 Yes

References