CVE-2020-7545
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/12/2020
Last modified:
03/09/2022
Description
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:schneider-electric:ecostruxure_energy_expert:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:power_manager:1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:power_manager:1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:power_manager:1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:powerscada_expert_with_advanced_reporting_and_dashboards:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:powerscada_operation_with_advanced_reporting_and_dashboards:9.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



