CVE-2020-7486

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remediated in version v10.5.x on August 13, 2009. TCMs from v10.5.x and on will no longer exhibit this behavior.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-205-01 Third Party Advisory US Government Resource
https://www.se.com/ww/en/download/document/SESB-2020-105-01 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:10.3.x:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:10.4.x:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4351:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:10.3.x:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:10.4.x:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4352:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:10.3.x:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:10.4.x:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4351a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:10.3.x:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:10.4.x:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4351b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:10.3.x:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:10.4.x:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4352a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:10.3.x:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:10.4.x:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4352b:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-04-16 19:15

Updated : 2024-02-28 17:47


NVD link : CVE-2020-7486

Mitre link : CVE-2020-7486

CVE.ORG link : CVE-2020-7486


JSON object : View

Products Affected

schneider-electric

  • tricon_tcm_4351b_firmware
  • tricon_tcm_4351_firmware
  • tricon_tcm_4352_firmware
  • tricon_tcm_4351a_firmware
  • tricon_tcm_4351a
  • tricon_tcm_4352
  • tricon_tcm_4351
  • tricon_tcm_4352a
  • tricon_tcm_4351b
  • tricon_tcm_4352b
  • tricon_tcm_4352b_firmware
  • tricon_tcm_4352a_firmware
CWE
CWE-400

Uncontrolled Resource Consumption