IM
IronMonkey Threat Research

CVE-2020-7545 HIGH

Published: 2020-12-01 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.

Additional Descriptions (1)

Una CWE-284: Se presenta una vulnerabilidad Control de Acceso Inapropiado en el Software EcoStruxureª y SmartStruxureª Power Monitoring and SCADA (véase la notificación de seguridad para la información de la versión) que podría permitir una ejecución de código arbitraria en el servidor cuando un usuario autorizado accede a una página web afectada

CVSS Metrics

Base Score: 7.2 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.2

Impact Score: 5.9

Base Score: 6.5 (MEDIUM)

AV:N/AC:L/Au:S/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.0

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-284
[email protected] Primary
en NVD-CWE-Other

Affected Products

Vendor Product Version Update Type
schneider-electric ecostruxure_energy_expert 2.0 <built-in method update of dict object at 0x7e60e8c7ff80> Application
schneider-electric ecostruxure_power_monitoring_expert 7.0 <built-in method update of dict object at 0x7e60e8c7ec40> Application
schneider-electric ecostruxure_power_monitoring_expert 8.0 <built-in method update of dict object at 0x7e61084065c0> Application
schneider-electric ecostruxure_power_monitoring_expert 9.0 <built-in method update of dict object at 0x7e60a88ac5c0> Application
schneider-electric power_manager 1.1 <built-in method update of dict object at 0x7e60a88ade00> Application
schneider-electric power_manager 1.2 <built-in method update of dict object at 0x7e60a88ae1c0> Application
schneider-electric power_manager 1.3 <built-in method update of dict object at 0x7e61084051c0> Application
schneider-electric powerscada_expert_with_advanced_reporting_and_dashboards 8.0 <built-in method update of dict object at 0x7e6108407180> Application
schneider-electric powerscada_operation_with_advanced_reporting_and_dashboards 9.0 <built-in method update of dict object at 0x7e60a88ad280> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_energy_expert:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:power_manager:1.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:power_manager:1.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:power_manager:1.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:powerscada_expert_with_advanced_reporting_and_dashboards:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:powerscada_operation_with_advanced_reporting_and_dashboards:9.0:*:*:*:*:*:*:*

References

Notification
Message here