CVE-2020-7547: High severity schneider electric ecostruxure energy expert vulnerability
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-7547.
What is the severity of CVE-2020-7547?
The severity of CVE-2020-7547 is high, with a severity score of 8.8.
Which software is affected by CVE-2020-7547?
The software affected by CVE-2020-7547 includes Schneider-electric Ecostruxure Energy Expert 2.0, Schneider-electric Ecostruxure Power Monitoring Expert 7.0, 8.0, and 9.0, Schneider-electric Power Manager 1.1, 1.2, and 1.3, Schneider-electric Powerscada Expert With Advanced Reporting And Dashboards 8.0, and Schneider-electric Powerscada Operation With Advanced Reporting And Dashboards 9.0.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-284.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by performing actions via the web interface at a higher privilege level.