CVE-2020-28217: High severity schneider electric easergy t300 vulnerability
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-28217?
CVE-2020-28217 is classified with a medium severity level due to the risk of sensitive data exposure through unencrypted HTTP communication.
How do I fix CVE-2020-28217?
To mitigate CVE-2020-28217, upgrade the Easergy T300 firmware to version 2.8 or later that provides enhanced security measures.
What type of data is vulnerable in CVE-2020-28217?
CVE-2020-28217 specifically affects sensitive data transmitted over the unencrypted HTTP protocol.
Who is affected by CVE-2020-28217?
CVE-2020-28217 affects Schneider Electric's Easergy T300 devices running firmware version 2.7 and earlier.
What does CVE-2020-28217 expose to attackers?
CVE-2020-28217 allows attackers to read potentially sensitive network traffic due to missing encryption.