PT-2020-19623 · Schneider Electric · Ecostruxure+1

Published

2020-12-01

·

Updated

2022-09-03

·

CVE-2020-7545

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure and SmartStruxure Power Monitoring and SCADA Software (affected versions not specified)
Description A CWE-284: Improper Access Control issue exists that could allow for arbitrary code execution on the server when an authorized user accesses an affected webpage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2020-7545

Affected Products

Ecostruxure
Smartstruxure Power Monitoring