---
cve: "CVE-2023-0595"
severity: "MEDIUM"
cvss: 5.3
epss: "42%"
vendor: "Schneider Electric"
kev: false
exploited: false
published: "2023-02-24 11:15:10"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-04T07:11:14+02:00"
---

# CVE-2023-0595

> 5.3 MEDIUM

## Beschreibung

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo SCADA Expert 2021(All Versions prior to October 2022), ClearSCADA (All Versions)

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-117** — Improper Output Neutralization for Logs
  The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

## Angriffsmuster (CAPEC)

- [CAPEC-81 — Web Server Logs Tampering](https://capec.mitre.org/data/definitions/81.html) _(Severity: High)_
- [CAPEC-93 — Log Injection-Tampering-Forging](https://capec.mitre.org/data/definitions/93.html) _(Severity: High)_
- [CAPEC-268 — Audit Log Manipulation](https://capec.mitre.org/data/definitions/268.html)

## ATT&CK-Techniken

- [T1070 — Indicator Removal on Host](https://attack.mitre.org/techniques/T1070/)
- [T1562.002 — Impair Defenses: Disable Windows Event Logging](https://attack.mitre.org/techniques/T1562/002/)
- [T1562.003 — Impair Defenses: Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1562.008 — Impair Defenses: Disable Cloud Logs](https://attack.mitre.org/techniques/T1562/008/)

## Referenzen

- <https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-045-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-045-01.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-0595) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
