PT-2019-5403 · Schneider Electric · Easergy Builder
Published
2019-08-21
·
Updated
2020-07-27
·
CVE-2020-7519
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Easergy Builder versions 1.4.7.2 and older
Description
A weakness in password requirements exists, which could allow an attacker to compromise a user account. The issue is related to weak password requirements, potentially enabling a remote attacker to exploit the vulnerability and compromise user credentials.
Recommendations
For Easergy Builder versions 1.4.7.2 and older, update to a version newer than 1.4.7.2 to resolve the issue. As a temporary workaround, consider strengthening password requirements to minimize the risk of exploitation. Restrict access to sensitive areas of the system to minimize the risk of compromised user accounts.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easergy Builder