CVE-2020-28216
published 2020-12-11CVE-2020-28216: A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.50%
39.3th percentile
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | easergy_t300_firmware | <= 2.7 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Easergy T300
cisa_ics·2020-12-08·CVSS 9.8
[CRITICAL] Schneider Electric Easergy T300
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Easergy T300
Last RevisedDecember 08, 2020
Alert CodeICSA-20-343-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely
- Vendor: Schneider Electric
- Equipment: Easergy T300
- Vulnerability: Missing Authentication for Critical Function, Missing Authorization, Missing Encryption of Sensitive Data, Improper Restriction of Rendered UI Layers or Frames
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to obtain unauthorized access to the internal product LAN, which could result in exposure of se
GHSA
GHSA-ggxv-vqqm-7f4w: A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2
ghsa_unreviewed·2022-05-24
CVE-2020-28216 [HIGH] CWE-311 GHSA-ggxv-vqqm-7f4w: A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-11
Published