CVE-2020-7545
 
Severity Score
7.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
Una CWE-284: Se presenta una vulnerabilidad Control de Acceso Inapropiado en el Software EcoStruxureª y SmartStruxureª Power Monitoring and SCADA (véase la notificación de seguridad para la información de la versión) que podría permitir una ejecución de código arbitraria en el servidor cuando un usuario autorizado accede a una página web afectada
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-01-21 CVE Reserved
- 2020-12-01 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-287-04 | 2022-09-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Energy Expert Search vendor "Schneider-electric" for product "Ecostruxure Energy Expert" | 2.0 Search vendor "Schneider-electric" for product "Ecostruxure Energy Expert" and version "2.0" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Power Monitoring Expert Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" | 7.0 Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" and version "7.0" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Power Monitoring Expert Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" | 8.0 Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" and version "8.0" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Power Monitoring Expert Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" | 9.0 Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" and version "9.0" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Power Manager Search vendor "Schneider-electric" for product "Power Manager" | 1.1 Search vendor "Schneider-electric" for product "Power Manager" and version "1.1" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Power Manager Search vendor "Schneider-electric" for product "Power Manager" | 1.2 Search vendor "Schneider-electric" for product "Power Manager" and version "1.2" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Power Manager Search vendor "Schneider-electric" for product "Power Manager" | 1.3 Search vendor "Schneider-electric" for product "Power Manager" and version "1.3" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Powerscada Expert With Advanced Reporting And Dashboards Search vendor "Schneider-electric" for product "Powerscada Expert With Advanced Reporting And Dashboards" | 8.0 Search vendor "Schneider-electric" for product "Powerscada Expert With Advanced Reporting And Dashboards" and version "8.0" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Powerscada Operation With Advanced Reporting And Dashboards Search vendor "Schneider-electric" for product "Powerscada Operation With Advanced Reporting And Dashboards" | 9.0 Search vendor "Schneider-electric" for product "Powerscada Operation With Advanced Reporting And Dashboards" and version "9.0" | - |
Affected
|