IM
IronMonkey Threat Research

CVE-2017-7969 HIGH

Published: 2017-09-26 | Last Modified: 2026-06-17 | Status: Modified

Description

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Additional Descriptions (1)

Existe una vulnerabilidad de Cross-Site Request Forgery (CSRF) en el componente Secure Gateway de PowerSCADA Anywhere v1.0 redistribuido con PowerSCADA Expert v8.1 y PowerSCADA Expert v8.2 y Citect Anywhere versión 1.0, de Schneider Electric para múltiples peticiones de cambio de estado. Este tipo de ataque requiere cierto nivel de ingeniería social para conseguir que un usuario legítimo haga clic o acceda a un enlace o página maliciosa que contenga el ataque CSRF.

CVSS Metrics

Base Score: 6.8 (MEDIUM)

AV:N/AC:M/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Primary
en CWE-352

Affected Products

Vendor Product Version Update Type
schneider-electric powerscada_anywhere 1.0 <built-in method update of dict object at 0x7e6107bcd600> Application
schneider-electric citect_anywhere 1.0 <built-in method update of dict object at 0x7e60b8461bc0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:powerscada_anywhere:1.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:a:schneider-electric:powerscada_expert:8.1:*:*:*:*:*:*:*
No cpe:2.3:a:schneider-electric:powerscada_expert:8.2:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:citect_anywhere:1.0:*:*:*:*:*:*:*

References

Notification
Message here