CVE-2020-28215
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.34% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- schneider-electric/easergy t300 firmware
- Source
- cybersecurity@se.com
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-03Third Party Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-06/Vendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-03Third Party Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-06/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.