PT-2020-5824 · Schneider Electric · Ecostruxure Building Operation Webreports

Published

2020-11-10

·

Updated

2022-09-03

·

CVE-2020-7573

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: EcoStruxure Building Operation WebReports versions 1.9 through 3.1
Description: A CWE-284 Improper Access Control issue exists that could allow a remote attacker to access restricted web resources due to improper access control, potentially leading to privilege escalation.
Recommendations: For versions 1.9 through 3.1, update to a version that includes the fix for this issue to prevent remote attackers from accessing restricted web resources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2021-01793
CVE-2020-7573

Affected Products

Ecostruxure Building Operation Webreports