CVE-2020-7491

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
schneiderCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
schneider-electrictricon_tcm_4351_firmware
10.2.0 ≤
𝑥
< 10.5.4
schneider-electrictricon_tcm_4352_firmware
10.2.0 ≤
𝑥
< 10.5.4
schneider-electrictricon_tcm_4351a_firmware
10.2.0 ≤
𝑥
< 10.5.4
schneider-electrictricon_tcm_4351b_firmware
10.2.0 ≤
𝑥
< 10.5.4
schneider-electrictricon_tcm_4352a_firmware
10.2.0 ≤
𝑥
< 10.5.4
schneider-electrictricon_tcm_4352b_firmware
10.2.0 ≤
𝑥
< 10.5.4
schneider-electrictristation_1131_firmware
1.0.0 ≤
𝑥
≤ 4.9.0
schneider-electrictristation_1131_firmware
4.10.0 ≤
𝑥
≤ 4.12.0
𝑥
= Vulnerable software versions