CVE-2020-7545: High severity schneider electric ecostruxure energy expert vulnerability
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this EcoStruxure vulnerability?
The vulnerability ID for this EcoStruxure vulnerability is CVE-2020-7545.
What is the title of the EcoStruxure vulnerability?
The title of the EcoStruxure vulnerability is 'A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.'
What is the severity level of CVE-2020-7545?
The severity level of CVE-2020-7545 is high with a value of 7.2.
Which software versions are affected by this EcoStruxure vulnerability?
The EcoStruxure vulnerability affects the following software versions: Schneider-electric Ecostruxure Energy Expert 2.0, Schneider-electric Ecostruxure Power Monitoring Expert 7.0, Schneider-electric Ecostruxure Power Monitoring Expert 8.0, Schneider-electric Ecostruxure Power Monitoring Expert 9.0, Schneider-electric Power Manager 1.1, Schneider-electric Power Manager 1.2, Schneider-electric Power Manager 1.3, Schneider-electric Powerscada Expert With Advanced Reporting And Dashboards 8.0, Schneider-electric Powerscada Operation With Advanced Reporting And Dashboards 9.0.
How can this vulnerability be fixed?
To fix this vulnerability, it is recommended to apply the security updates provided by Schneider Electric. Please refer to the reference link for more information.