CVE-2020-7504: Input Validation
A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable the webserver service on the device when specially crafted network packets are sent.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7504?
CVE-2020-7504 has a medium severity rating due to its potential to disable the webserver service on the Easergy T300 device.
How do I fix CVE-2020-7504?
To fix CVE-2020-7504, update the Easergy T300 firmware to a version newer than 1.5.2.
What devices are affected by CVE-2020-7504?
CVE-2020-7504 affects Schneider Electric Easergy T300 devices running firmware version 1.5.2 or older.
What could an attacker do exploiting CVE-2020-7504?
An attacker exploiting CVE-2020-7504 could disable the webserver service on the Easergy T300 device using specially crafted network packets.
Is there a workaround for CVE-2020-7504?
There are no official workarounds for CVE-2020-7504; updating the firmware is the recommended approach.