First published: Tue Jun 16 2020(Updated: )
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Easergy T300 Firmware | <=1.5.2 | |
Schneider Electric Easergy T300 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7508 has a high severity rating due to the potential for an attacker to gain full access through brute force methods.
To fix CVE-2020-7508, it is recommended to upgrade the Easergy T300 firmware to version 1.5.3 or later.
CVE-2020-7508 affects Schneider Electric Easergy T300 firmware versions 1.5.2 and older.
CVE-2020-7508 is classified as a CWE-307 vulnerability, related to improper restriction of excessive authentication attempts.
Yes, CVE-2020-7508 can be exploited remotely, allowing attackers to attempt brute force attacks from outside the network.