IM
IronMonkey Threat Research

CVE-2020-7486 HIGH

Published: 2020-04-16 | Last Modified: 2024-11-21 | Status: Modified

Description

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remediated in version v10.5.x on August 13, 2009. TCMs from v10.5.x and on will no longer exhibit this behavior.

Additional Descriptions (1)

**VERSIÓN NO COMPATIBLE CUANDO SE ASIGNÓ** Una vulnerabilidad podría causar que los módulos TCM se restablezcan cuando se encuentren bajo una alta carga de red en TCM versión v10.4.x y en el system versión v10.3.x. Esta vulnerabilidad fue descubierta y corregida en la versión v10.5.x el 13 de agosto de 2009. Los TCM a partir de la versión v10.5.x ya no mostrarán este comportamiento.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Base Score: 5.0 (MEDIUM)

AV:N/AC:L/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-400

Affected Products

Vendor Product Version Update Type
schneider-electric tricon_tcm_4351_firmware 10.3.x <built-in method update of dict object at 0x7e60a888f440> Operating System
schneider-electric tricon_tcm_4351_firmware 10.4.x <built-in method update of dict object at 0x7e60a888c380> Operating System
schneider-electric tricon_tcm_4352_firmware 10.3.x <built-in method update of dict object at 0x7e60a888d140> Operating System
schneider-electric tricon_tcm_4352_firmware 10.4.x <built-in method update of dict object at 0x7e60e88158c0> Operating System
schneider-electric tricon_tcm_4351a_firmware 10.3.x <built-in method update of dict object at 0x7e60a888d680> Operating System
schneider-electric tricon_tcm_4351a_firmware 10.4.x <built-in method update of dict object at 0x7e60a888e600> Operating System
schneider-electric tricon_tcm_4351b_firmware 10.3.x <built-in method update of dict object at 0x7e60a888f600> Operating System
schneider-electric tricon_tcm_4351b_firmware 10.4.x <built-in method update of dict object at 0x7e60a888e580> Operating System
schneider-electric tricon_tcm_4352a_firmware 10.3.x <built-in method update of dict object at 0x7e60a88aea00> Operating System
schneider-electric tricon_tcm_4352a_firmware 10.4.x <built-in method update of dict object at 0x7e60a888dc80> Operating System
schneider-electric tricon_tcm_4352b_firmware 10.3.x <built-in method update of dict object at 0x7e60a88ac5c0> Operating System
schneider-electric tricon_tcm_4352b_firmware 10.4.x <built-in method update of dict object at 0x7e60a888dbc0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:10.3.x:*:*:*:*:*:*:*
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:10.4.x:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:tricon_tcm_4351:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:10.3.x:*:*:*:*:*:*:*
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:10.4.x:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:tricon_tcm_4352:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:10.3.x:*:*:*:*:*:*:*
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:10.4.x:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:tricon_tcm_4351a:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:10.3.x:*:*:*:*:*:*:*
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:10.4.x:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:tricon_tcm_4351b:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:10.3.x:*:*:*:*:*:*:*
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:10.4.x:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:tricon_tcm_4352a:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:10.3.x:*:*:*:*:*:*:*
Yes cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:10.4.x:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:tricon_tcm_4352b:-:*:*:*:*:*:*:*

References

Notification
Message here