PT-2019-5403 · Schneider Electric · Easergy Builder

Publicado

2019-08-21

·

Atualizado

2020-07-27

·

CVE-2020-7519

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easergy Builder versions 1.4.7.2 and older
Description A weakness in password requirements exists, which could allow an attacker to compromise a user account. The issue is related to weak password requirements, potentially enabling a remote attacker to exploit the vulnerability and compromise user credentials.
Recommendations For Easergy Builder versions 1.4.7.2 and older, update to a version newer than 1.4.7.2 to resolve the issue. As a temporary workaround, consider strengthening password requirements to minimize the risk of exploitation. Restrict access to sensitive areas of the system to minimize the risk of compromised user accounts.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02736
CVE-2020-7519

Produtos afetados

Easergy Builder