CVE-2021-22741
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. Note that “.sde” configuration export files do not contain user account password hashes.
Una vulnerabilidad de Uso de Contraseña Hash con vulnerabilidad con Esfuerzo Computacional Insuficiente se presenta en ClearSCADA (todas las versiones), EcoStruxure Geo SCADA Expert 2019 (todas las versiones) y EcoStruxure Geo SCADA Expert 2020 (versiones V83.7742.1 y anteriores), que podría causar la revelación de las credenciales de la cuenta cuando los archivos de la base de datos del servidor están disponibles. La exposición de estos archivos a un atacante puede hacer que el sistema sea vulnerable a los ataques de descifrado de contraseñas. Tome en cuenta que los archivos de exportación de configuración ".sde" no contienen hashes de contraseña de cuenta de usuario
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-06 CVE Reserved
- 2021-05-26 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-916: Use of Password Hash With Insufficient Computational Effort
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-07 | 2021-06-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Clearscada Search vendor "Schneider-electric" for product "Clearscada" | * | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Geo Scada Expert 2019 Search vendor "Schneider-electric" for product "Ecostruxure Geo Scada Expert 2019" | * | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Geo Scada Expert 2020 Search vendor "Schneider-electric" for product "Ecostruxure Geo Scada Expert 2020" | <= 83.7742.1 Search vendor "Schneider-electric" for product "Ecostruxure Geo Scada Expert 2020" and version " <= 83.7742.1" | - |
Affected
|