First published: Mon Aug 31 2020(Updated: )
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric Modbus Driver Suite | <14.15.0.0 | |
schneider-electric Modbus Driver suite | <2.20_ie_30 | |
schneider-electric Modbus Driver suite | <3.20_ie_30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7523 has a high severity rating due to the potential for local privilege escalation.
To mitigate CVE-2020-7523, update the Schneider Electric Modbus Serial Driver to a version that is not affected.
CVE-2020-7523 affects versions of Schneider Electric Modbus Driver Suite up to but not including 14.15.0.0.
CVE-2020-7523 is primarily a local privilege escalation vulnerability, thus it requires local access to exploit.
Yes, a patch for CVE-2020-7523 is available through updates from Schneider Electric.