PT-2020-6374 · Schneider Electric · Easergy T300
Evgeniy Druzhinin
+1
·
Published
2020-11-10
·
Updated
2020-12-14
·
CVE-2020-28218
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Easergy T300 versions 2.7 and older
Description
The issue is related to errors in the representation of information by the user interface, which can be exploited by a remote attacker to perform arbitrary actions. This is due to improper restriction of rendered UI layers or frames, allowing an attacker to trick a user into initiating an unintended action.
Recommendations
For versions 2.7 and older, update the firmware to a version newer than 2.7 to resolve the issue.
As a temporary workaround, consider restricting access to the user interface to minimize the risk of exploitation.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easergy T300