A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the archive with the firmware for the controller and modules using the usual tar archiver resulting in an information exposure.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2020-161-04 - |
Information
Published : 2020-06-16 20:15
Updated : 2024-11-21 05:37
NVD link : CVE-2020-7506
Mitre link : CVE-2020-7506
CVE.ORG link : CVE-2020-7506
JSON object : View
Products Affected
schneider-electric
- easergy_t300_firmware
- easergy_t300
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor