CVE-2020-7561
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly restricted.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.16% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-306
- Affected
- schneider-electric/easergy t300 firmware
- Source
- cybersecurity@se.com
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-03Third Party Advisory, US Government Resource
- https://www.se.com/ww/en/download/document/SEVD-2020-315-06/Patch, Product, Vendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-03Third Party Advisory, US Government Resource
- https://www.se.com/ww/en/download/document/SEVD-2020-315-06/Patch, Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.