cbcvebase.
CVE-2020-7545
published 2020-12-01

CVE-2020-7545: A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.

Affected

9 ranges
VendorProductVersion rangeFixed in
schneider-electricecostruxure_energy_expert
schneider-electricecostruxure_power_monitoring_expert
schneider-electricecostruxure_power_monitoring_expert
schneider-electricecostruxure_power_monitoring_expert
schneider-electricpower_manager
schneider-electricpower_manager
schneider-electricpower_manager
schneider-electricpowerscada_expert_with_advanced_reporting_and_dashboards
schneider-electricpowerscada_operation_with_advanced_reporting_and_dashboards
CVE-2020-7545 — Improper Access Control | cvebase