CVE-2020-7505
Published on: 06/16/2020 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:23:54 PM UTC
Certain versions of Easergy T300 from Schneider-electric contain the following vulnerability:
A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to inject data with dangerous content into the firmware and execute arbitrary code on the system.
- CVE-2020-7505 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Notification - Easergy T300 | Schneider Electric | Vendor Advisory www.se.com text/html |
![]() |
Related QID Numbers
- 590772 Schneider Electric Easergy T300 Multiple Vulnerabilities (SEVD-2020-161-04)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware | Schneider-electric | Easergy T300 | - | All | All | All |
Hardware | Schneider-electric | Easergy T300 | - | All | All | All |
Operating System | Schneider-electric | Easergy T300 Firmware | All | All | All | All |
- cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:*:
- cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:*:
- cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE