PT-2019-5396 · Schneider Electric · Easergy T300

Published

2019-06-12

·

Updated

2020-06-19

·

CVE-2020-7512

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easergy T300 versions 1.5.2 and older
Description A vulnerability exists due to the use of platform-dependent third-party components with vulnerabilities in the Easergy T300. This could allow an attacker to exploit the component, potentially enabling various attacks on these components. The issue is related to the use of vulnerable third-party software.
Recommendations For Easergy T300 versions 1.5.2 and older, update the firmware to a version newer than 1.5.2 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02729
CVE-2020-7512

Affected Products

Easergy T300