PT-2019-5398 · Schneider Electric · Easergy Builder

Publicado

2019-08-21

·

Atualizado

2020-07-27

·

CVE-2020-7514

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easergy Builder versions 1.4.7.2 and older
Description The issue is related to the use of an insufficiently secure encryption algorithm, which could allow an attacker to gain access to user credentials and subsequently achieve full access to the device.
Recommendations For Easergy Builder versions 1.4.7.2 and older, update to a version that uses a secure encryption algorithm to prevent exploitation. As a temporary workaround, consider restricting access to the device to minimize the risk of unauthorized access until a secure version is available.

Correção

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02731
CVE-2020-7514

Produtos afetados

Easergy Builder