PT-2019-5397 · Schneider Electric · Easergy T300

Publicado

2019-06-12

·

Atualizado

2020-06-17

·

CVE-2020-7513

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easergy T300 versions 1.5.2 and older
Description The issue is related to the storage and transmission of critical data in an unencrypted form. This could allow a remote attacker to intercept traffic and obtain configuration information about the device.
Recommendations For versions 1.5.2 and older, update to a version newer than 1.5.2 to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02730
CVE-2020-7513

Produtos afetados

Easergy T300