PT-2020-6344 · Schneider Electric · Power Monitoring Expert+5

Published

2020-10-13

·

Updated

2022-09-03

·

CVE-2020-7547

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure and SmartStruxure Power Monitoring and SCADA Software (affected versions not specified) Power Monitoring Expert (affected versions not specified) EcoStruxure Energy Expert (affected versions not specified) Power Manager (affected versions not specified) StruxureWare PowerSCADA Expert (affected versions not specified)
Description A vulnerability exists in the software that could allow a user to perform actions via the web interface at a higher privilege level due to improper access control. This issue is related to deficiencies in access control, which could allow a remote attacker to elevate their privileges.
Recommendations For EcoStruxure and SmartStruxure Power Monitoring and SCADA Software, consider restricting access to the web interface until a patch is available. For Power Monitoring Expert, EcoStruxure Energy Expert, Power Manager, and StruxureWare PowerSCADA Expert, restrict access to sensitive areas of the software to minimize the risk of exploitation. As a temporary workaround, consider disabling remote access to the software until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2021-04256
CVE-2020-7547

Affected Products

Ecostruxure
Ecostruxure Energy Expert
Power Manager
Power Monitoring Expert
Smartstruxure
Struxureware Powerscada Expert