CVE-2020-7545

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:schneider-electric:ecostruxure_energy_expert:2.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:power_manager:1.1:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:power_manager:1.2:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:power_manager:1.3:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:powerscada_expert_with_advanced_reporting_and_dashboards:8.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:powerscada_operation_with_advanced_reporting_and_dashboards:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
References () https://www.se.com/ww/en/download/document/SEVD-2020-287-04/ - Vendor Advisory () https://www.se.com/ww/en/download/document/SEVD-2020-287-04/ - Vendor Advisory

Information

Published : 2020-12-01 15:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7545

Mitre link : CVE-2020-7545

CVE.ORG link : CVE-2020-7545


JSON object : View

Products Affected

schneider-electric

  • ecostruxure_energy_expert
  • powerscada_expert_with_advanced_reporting_and_dashboards
  • ecostruxure_power_monitoring_expert
  • powerscada_operation_with_advanced_reporting_and_dashboards
  • power_manager
CWE
CWE-284

Improper Access Control

NVD-CWE-Other