← Vulnerability feed

Vulnerability record · CVE-2017-6021 · published 14 May 2018

CVE-2017-6021: Aveva clearscada improper input validation vulnerability

Aveva · Clearscada

In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

7.5 CVSS 3.0 High EPSS 1.7% · top 24.2% CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/96768 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-068-01 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/96768 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-17-068-01 Third Party AdvisoryUS Government Resource

Track CVE-2017-6021 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-3143Aveva clearscada vulnerabilityUse-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9,…EPSS 7.5%7.8CVE-2019-6854Schneider-electric clearscada improper authentication vulnerabilityA CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 …EPSS 0.17%7.5CVE-2022-24318Schneider-electric clearscada inadequate encryption strength vulnerabilityA CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of…EPSS 0.39%7.5CVE-2022-24321Schneider-electric clearscada vulnerabilityA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server …EPSS 1.00%7.5CVE-2017-9962Aveva clearscada memory buffer overflow vulnerabilitySchneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed reques…EPSS 1.0%6.8CVE-2014-0779Aveva clearscada memory buffer overflow vulnerabilityThe PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4…EPSS 1.5%6.7CVE-2021-22741Schneider-electric clearscada vulnerabilityUse of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all…EPSS 0.17%6.4CVE-2014-5412Aveva clearscada improper authentication vulnerabilitySchneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2017-6021), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.