CVE-2020-7545

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:schneider-electric:ecostruxure_energy_expert:2.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:power_manager:1.1:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:power_manager:1.2:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:power_manager:1.3:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:powerscada_expert_with_advanced_reporting_and_dashboards:8.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:powerscada_operation_with_advanced_reporting_and_dashboards:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
References () https://www.se.com/ww/en/download/document/SEVD-2020-287-04/ - Vendor Advisory () https://www.se.com/ww/en/download/document/SEVD-2020-287-04/ - Vendor Advisory

03 Sep 2022, 03:46

Type Values Removed Values Added
CWE CWE-284 NVD-CWE-Other

Information

Published : 2020-12-01 15:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7545

Mitre link : CVE-2020-7545

CVE.ORG link : CVE-2020-7545


JSON object : View

Products Affected

schneider-electric

  • ecostruxure_power_monitoring_expert
  • powerscada_expert_with_advanced_reporting_and_dashboards
  • powerscada_operation_with_advanced_reporting_and_dashboards
  • power_manager
  • ecostruxure_energy_expert
CWE
CWE-284

Improper Access Control

NVD-CWE-Other