CVE-2020-7548

EUVD-2020-28673
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
schneider-electricacti9_smartlink_si_d_firmware
𝑥
< 002.004.002
schneider-electricacti9_smartlink_si_b_firmware
𝑥
< 002.004.002
schneider-electricacti9_powertag_link_firmware
𝑥
< 001.008.007
schneider-electricacti9_powertag_link_hd_firmware
𝑥
< 001.008.007
schneider-electricacti9_smartlink_el_b_firmware
𝑥
< 1.2.1
schneider-electricwiser_link_firmware
𝑥
< 1.5.0
schneider-electricwiser_energy_firmware
𝑥
< 1.5.0
𝑥
= Vulnerable software versions