Vulnerabilities > CVE-2022-24317 - Missing Authorization vulnerability in Schneider-Electric Interactive Graphical Scada System Data Server

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
schneider-electric
CWE-862

Summary

A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

Vulnerable Configurations

Part Description Count
Application
Schneider-Electric
1

Common Weakness Enumeration (CWE)