// For flags

CVE-2020-7546

 

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an affected webpage.

Una CWE-79: Se presenta una vulnerabilidad Neutralización Inapropiada de la Entrada Durante la Generación de Páginas Web en el Software EcoStruxureª y SmartStruxureª Power Monitoring and SCADA (véase la notificación de seguridad para la información de la versión) que podría permitir a un atacante llevar a cabo acciones en nombre del usuario autorizado cuando se acceder a un página web afectada

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-21 CVE Reserved
  • 2020-12-01 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Schneider-electric
Search vendor "Schneider-electric"
Ecostruxure Energy Expert
Search vendor "Schneider-electric" for product "Ecostruxure Energy Expert"
2.0
Search vendor "Schneider-electric" for product "Ecostruxure Energy Expert" and version "2.0"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Ecostruxure Power Monitoring Expert
Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert"
7.0
Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" and version "7.0"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Ecostruxure Power Monitoring Expert
Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert"
8.0
Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" and version "8.0"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Ecostruxure Power Monitoring Expert
Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert"
9.0
Search vendor "Schneider-electric" for product "Ecostruxure Power Monitoring Expert" and version "9.0"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Power Manager
Search vendor "Schneider-electric" for product "Power Manager"
1.1
Search vendor "Schneider-electric" for product "Power Manager" and version "1.1"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Power Manager
Search vendor "Schneider-electric" for product "Power Manager"
1.2
Search vendor "Schneider-electric" for product "Power Manager" and version "1.2"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Power Manager
Search vendor "Schneider-electric" for product "Power Manager"
1.3
Search vendor "Schneider-electric" for product "Power Manager" and version "1.3"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Powerscada Expert With Advanced Reporting And Dashboards
Search vendor "Schneider-electric" for product "Powerscada Expert With Advanced Reporting And Dashboards"
8.0
Search vendor "Schneider-electric" for product "Powerscada Expert With Advanced Reporting And Dashboards" and version "8.0"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Powerscada Operation With Advanced Reporting And Dashboards
Search vendor "Schneider-electric" for product "Powerscada Operation With Advanced Reporting And Dashboards"
9.0
Search vendor "Schneider-electric" for product "Powerscada Operation With Advanced Reporting And Dashboards" and version "9.0"
-
Affected