CVE-2017-6021 is a denial-of-service vulnerability affecting Schneider Electric ClearSCADA versions 2014 R1, 2014 R1.1, 2015 R1, and 2015 R2. An unauthenticated attacker with network access can send specially crafted data to the ClearSCADA server, causing the server and communication driver processes to terminate. This vulnerability has a CVSS v3 base score of 7.5 (High), indicating a high impact on availability with low attack complexity and no user interaction required. There is no evidence of active exploitation, nor is public exploit code available, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2010CPE matchmatch criteria | cpe:2.3:a:aveva:clearscada:*:*:*:*:*:*:*:* | ||
2014CPE matchmatch criteria | cpe:2.3:a:schneider-electric:clearscada:2014:r1:*:*:*:*:*:* | ||
2014CPE matchmatch criteria | cpe:2.3:a:schneider-electric:clearscada:2014:r1.1:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:schneider-electric:clearscada:2015:r1:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:schneider-electric:clearscada:2015:r2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.