CVE-2020-7547
01.12.2020, 15:15
A CWE-284: Improper Access Control vulnerability exists in EcoStruxure and SmartStruxure Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | ecostruxure_energy_expert | 2.0 |
schneider-electric | ecostruxure_power_monitoring_expert | 7.0 |
schneider-electric | ecostruxure_power_monitoring_expert | 8.0 |
schneider-electric | ecostruxure_power_monitoring_expert | 9.0 |
schneider-electric | power_manager | 1.1 |
schneider-electric | power_manager | 1.2 |
schneider-electric | power_manager | 1.3 |
schneider-electric | powerscada_expert_with_advanced_reporting_and_dashboards | 8.0 |
schneider-electric | powerscada_operation_with_advanced_reporting_and_dashboards | 9.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration