CVE-2020-7491
Summary
| CVE | CVE-2020-7491 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-23 21:15:00 UTC |
| Updated | 2022-04-27 16:28:00 UTC |
| Description | **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin - Legacy Triconex Product Vulnerabilities (V2.1) | Schneider Electric | MISC | www.se.com | Vendor Advisory |
| Schneider Electric Triconex TriStation and Tricon Communication Module | CISA | MISC | us-cert.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591256 Schneider Electric Tricon Communication Module Multiple Vulnerabilities (ICSA-20-205-01, SESB-2020-105-01)