ZeroHour

CVE-2020-7545

CVSS 3.1
7.2 high
EPSS
2%p80
Published
()
Modified
Description

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.

Vendors
schneider-electric
Products
ecostruxure energy expert, ecostruxure power monitoring expert, power manager, powerscada expert with advanced reporting and dashboards, powerscada operation with advanced reporting and dashboards
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.