← Vulnerability feed

Vulnerability record · CVE-2023-22610 · published 31 January 2023

CVE-2023-22610: Schneider-electric ecostruxure geo scada expert 2019 incorrect authorization vulnerability

Schneider Electric · Ecostruxure Geo Scada Expert 2019

A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.

7.5 CVSS 3.1 High EPSS 0.57% · top 55.0% CWE-863 · Incorrect authorization
7.5CVSS 3.1 base score
0.57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22610 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-28219Schneider-electric ecostruxure geo scada expert 2019 insufficiently protected credentials vulnerabilityA CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to Se…EPSS 0.31%7.5CVE-2023-22611Schneider-electric ecostruxure geo scada expert 2019 information exposure vulnerabilityA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific mess…EPSS 0.57%7.5CVE-2022-24318Schneider-electric clearscada inadequate encryption strength vulnerabilityA CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of…EPSS 0.39%7.5CVE-2022-24321Schneider-electric clearscada vulnerabilityA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server …EPSS 1.00%6.7CVE-2021-22741Schneider-electric clearscada vulnerabilityUse of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all…EPSS 0.17%5.9CVE-2022-24319Schneider-electric clearscada improper certificate validation vulnerabilityA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…EPSS 0.58%5.9CVE-2022-24320Schneider-electric clearscada improper certificate validation vulnerabilityA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…EPSS 0.54%5.3CVE-2023-0595Schneider-electric clearscada vulnerabilityA CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets ar…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2023-22610), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.