CVE-2020-28215
published 2020-12-11CVE-2020-28215: A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.24%
80.8th percentile
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | easergy_t300_firmware | <= 2.7 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Easergy T300
cisa_ics·2020-12-08·CVSS 9.8
[CRITICAL] Schneider Electric Easergy T300
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Easergy T300
Last RevisedDecember 08, 2020
Alert CodeICSA-20-343-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely
- Vendor: Schneider Electric
- Equipment: Easergy T300
- Vulnerability: Missing Authentication for Critical Function, Missing Authorization, Missing Encryption of Sensitive Data, Improper Restriction of Rendered UI Layers or Frames
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to obtain unauthorized access to the internal product LAN, which could result in exposure of se
GHSA
GHSA-9ggp-g58q-5q4w: A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2
ghsa_unreviewed·2022-05-24
CVE-2020-28215 [CRITICAL] CWE-862 GHSA-9ggp-g58q-5q4w: A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-11
Published