IM
IronMonkey Threat Research

CVE-2021-22741 MEDIUM

Published: 2021-05-26 | Last Modified: 2024-11-21 | Status: Modified

Description

Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. Note that “.sde” configuration export files do not contain user account password hashes.

Additional Descriptions (1)

Una vulnerabilidad de Uso de Contraseña Hash con vulnerabilidad con Esfuerzo Computacional Insuficiente se presenta en ClearSCADA (todas las versiones), EcoStruxure Geo SCADA Expert 2019 (todas las versiones) y EcoStruxure Geo SCADA Expert 2020 (versiones V83.7742.1 y anteriores), que podría causar la revelación de las credenciales de la cuenta cuando los archivos de la base de datos del servidor están disponibles. La exposición de estos archivos a un atacante puede hacer que el sistema sea vulnerable a los ataques de descifrado de contraseñas. Tome en cuenta que los archivos de exportación de configuración ".sde" no contienen hashes de contraseña de cuenta de usuario

CVSS Metrics

Base Score: 6.7 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 0.8

Impact Score: 5.9

Base Score: 4.6 (MEDIUM)

AV:L/AC:L/Au:N/C:P/I:P/A:P

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-916

Affected Products

Vendor Product Version Update Type
schneider-electric clearscada * <built-in method update of dict object at 0x7e60e884ef80> Application
schneider-electric ecostruxure_geo_scada_expert_2019 * <built-in method update of dict object at 0x7e61109d4c00> Application
schneider-electric ecostruxure_geo_scada_expert_2020 * <built-in method update of dict object at 0x7e60e884cdc0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:clearscada:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:*:*:*:*:*:*:*:*
Notification
Message here