← Vulnerability feed

Vulnerability record · CVE-2022-24319 · published 9 February 2022

CVE-2022-24319: Schneider-electric clearscada improper certificate validation vulnerability

Schneider Electric · Clearscada

A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)

5.9 CVSS 3.1 Medium EPSS 0.58% · top 54.7% CWE-295 · Improper certificate validation
5.9CVSS 3.1 base score, v2 4.3
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24319 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-28219Schneider-electric ecostruxure geo scada expert 2019 insufficiently protected credentials vulnerabilityA CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to Se…EPSS 0.31%7.8CVE-2019-6854Schneider-electric clearscada improper authentication vulnerabilityA CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 …EPSS 0.17%7.5CVE-2023-22610Schneider-electric ecostruxure geo scada expert 2019 incorrect authorization vulnerabilityA CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are se…EPSS 0.57%7.5CVE-2023-22611Schneider-electric ecostruxure geo scada expert 2019 information exposure vulnerabilityA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific mess…EPSS 0.57%7.5CVE-2022-24318Schneider-electric clearscada inadequate encryption strength vulnerabilityA CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of…EPSS 0.39%7.5CVE-2022-24321Schneider-electric clearscada vulnerabilityA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server …EPSS 1.00%7.5CVE-2017-6021Aveva clearscada improper input validation vulnerabilityIn Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 …EPSS 1.7%6.7CVE-2021-22741Schneider-electric clearscada vulnerabilityUse of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2022-24319), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.