PT-2019-5397 · Schneider Electric · Easergy T300

Published

2019-06-12

·

Updated

2020-06-17

·

CVE-2020-7513

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easergy T300 versions 1.5.2 and older
Description The issue is related to the storage and transmission of critical data in an unencrypted form. This could allow a remote attacker to intercept traffic and obtain configuration information about the device.
Recommendations For versions 1.5.2 and older, update to a version newer than 1.5.2 to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02730
CVE-2020-7513

Affected Products

Easergy T300