PT-2019-5402 · Schneider Electric · Easergy Builder

Published

2019-08-21

·

Updated

2020-07-27

·

CVE-2020-7518

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions Easergy Builder versions 1.4.7.2 and older
Description The issue is related to improper input validation in the Easergy Builder software, which could allow a remote attacker to modify project configuration files.
Recommendations For Easergy Builder versions 1.4.7.2 and older, update to a version newer than 1.4.7.2 to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02735
CVE-2020-7518

Affected Products

Easergy Builder