CVE-2020-7491

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4.
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-205-01 Third Party Advisory US Government Resource
https://www.se.com/ww/en/download/document/SESB-2020-105-01/ Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4351:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4352:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4351a:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4351b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4352a:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tricon_tcm_4352b:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:schneider-electric:tristation_1131_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:tristation_1131_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:tristation_1131:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-07-23 21:15

Updated : 2024-02-28 17:47


NVD link : CVE-2020-7491

Mitre link : CVE-2020-7491

CVE.ORG link : CVE-2020-7491


JSON object : View

Products Affected

schneider-electric

  • tricon_tcm_4351b_firmware
  • tristation_1131
  • tricon_tcm_4351_firmware
  • tristation_1131_firmware
  • tricon_tcm_4352_firmware
  • tricon_tcm_4351a_firmware
  • tricon_tcm_4351a
  • tricon_tcm_4352
  • tricon_tcm_4351
  • tricon_tcm_4352a
  • tricon_tcm_4351b
  • tricon_tcm_4352b
  • tricon_tcm_4352b_firmware
  • tricon_tcm_4352a_firmware