cbcvebase.

Schneider-Electric Easergy T300 Firmware vulnerabilities

24 known vulnerabilities affecting schneider-electric/easergy_t300_firmware.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH12MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2020-28218P4MEDIUMCVSS 6.5≤ 2.72020-12-11
CVE-2020-28218 [MEDIUM] CWE-1021 CVE-2020-28218: A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T30 A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.
nvd
CVE-2020-7504P4MEDIUMCVSS 5.3≤ 1.5.22020-06-16
CVE-2020-7504 [MEDIUM] CWE-20 CVE-2020-7504: A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable the webserver service on the device when specially crafted network packets are sent.
nvd
CVE-2020-25184P4MEDIUMCVSS 5.5≤ 2.7.12022-03-18
CVE-2020-25184 [MEDIUM] CWE-256 CVE-2020-25184: Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information d
nvd
CVE-2021-22769P4MEDIUMCVSS 4.3≤ 2.7.12021-06-11
CVE-2021-22769 [MEDIUM] CWE-552 CVE-2021-22769: A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
nvd
Schneider-Electric Easergy T300 Firmware vulnerabilities | cvebase