CVE-2020-28215

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2020
Last modified:
14/12/2020

Description

A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:* 2.7 (including)
cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:*