Show plain JSON{"id": "CVE-2021-22741", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.6, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.7, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "HIGH", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 0.8}]}, "published": "2021-05-26T20:15:09.253", "references": [{"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-07", "tags": ["Patch", "Vendor Advisory"], "source": "cybersecurity@se.com"}, {"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-07", "tags": ["Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "cybersecurity@se.com", "description": [{"lang": "en", "value": "CWE-916"}]}], "descriptions": [{"lang": "en", "value": "Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. Note that \u201c.sde\u201d configuration export files do not contain user account password hashes."}, {"lang": "es", "value": "Una vulnerabilidad de Uso de Contrase\u00f1a Hash con vulnerabilidad con Esfuerzo Computacional Insuficiente se presenta en ClearSCADA (todas las versiones), EcoStruxure Geo SCADA Expert 2019 (todas las versiones) y EcoStruxure Geo SCADA Expert 2020 (versiones V83.7742.1 y anteriores), que podr\u00eda causar la revelaci\u00f3n de las credenciales de la cuenta cuando los archivos de la base de datos del servidor est\u00e1n disponibles. La exposici\u00f3n de estos archivos a un atacante puede hacer que el sistema sea vulnerable a los ataques de descifrado de contrase\u00f1as. Tome en cuenta que los archivos de exportaci\u00f3n de configuraci\u00f3n \".sde\" no contienen hashes de contrase\u00f1a de cuenta de usuario"}], "lastModified": "2024-11-21T05:50:34.430", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:schneider-electric:clearscada:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8117E9AF-97C7-4C10-BE59-5341D32667F4"}, {"criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2019:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "665F4C4F-CC00-4484-B6FD-5E77EDBCD242"}, {"criteria": "cpe:2.3:a:schneider-electric:ecostruxure_geo_scada_expert_2020:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C71E313-FBE3-4B14-9176-362FB6A409BE", "versionEndIncluding": "83.7742.1"}], "operator": "OR"}]}], "sourceIdentifier": "cybersecurity@se.com"}