PT-2019-5392 · Schneider Electric · Easergy T300

Published

2019-06-12

·

Updated

2020-06-17

·

CVE-2020-7508

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easergy T300 versions 1.5.2 and older
Description A vulnerability exists due to improper restriction of excessive authentication attempts, which could allow an attacker to gain full access by brute force. This issue may be exploited by a remote attacker to obtain full access.
Recommendations For Easergy T300 versions 1.5.2 and older, update the firmware to a version newer than 1.5.2 to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02725
CVE-2020-7508

Affected Products

Easergy T300