← Vulnerability feed

Vulnerability record · CVE-2019-6854 · published 6 January 2020

CVE-2019-6854: Schneider-electric clearscada improper authentication vulnerability

Schneider Electric · Clearscada

A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vulnerability. Affected versions in current support includes ClearSCADA 2017 R3, ClearSCADA 2017 R2, and ClearSCADA 2017.

7.8 CVSS 3.1 High EPSS 0.17% · top 94.7% CWE-287 · Improper authentication
7.8CVSS 3.1 base score, v2 4.6
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vulnerability. Affected versions in current support includes ClearSCADA 2017 R3, ClearSCADA 2017 R2, and ClearSCADA 2017.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-6854 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-24318Schneider-electric clearscada inadequate encryption strength vulnerabilityA CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of…EPSS 0.39%7.5CVE-2022-24321Schneider-electric clearscada vulnerabilityA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server …EPSS 1.00%7.5CVE-2017-6021Aveva clearscada improper input validation vulnerabilityIn Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 …EPSS 1.7%6.7CVE-2021-22741Schneider-electric clearscada vulnerabilityUse of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all…EPSS 0.17%5.9CVE-2022-24319Schneider-electric clearscada improper certificate validation vulnerabilityA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…EPSS 0.58%5.9CVE-2022-24320Schneider-electric clearscada improper certificate validation vulnerabilityA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…EPSS 0.54%5.3CVE-2023-0595Schneider-electric clearscada vulnerabilityA CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets ar…EPSS 0.42%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed

Source: NIST National Vulnerability Database (record CVE-2019-6854), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.