IM
IronMonkey Threat Research

CVE-2020-7547 HIGH

Published: 2020-12-01 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.

Additional Descriptions (1)

Una CWE-284: Se presenta una vulnerabilidad Control de Acceso Inapropiado en el Software EcoStruxureª y SmartStruxureª Power Monitoring and SCADA (véase la notificación de seguridad para la información de la versión) que podría permitir a un usuario la habilidad para llevar a cabo acciones por medio de la interfaz web en un nivel de privilegio elevado

CVSS Metrics

Base Score: 8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 5.9

Base Score: 6.5 (MEDIUM)

AV:N/AC:L/Au:S/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.0

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-284
[email protected] Primary
en NVD-CWE-Other

Affected Products

Vendor Product Version Update Type
schneider-electric ecostruxure_energy_expert 2.0 <built-in method update of dict object at 0x7e6111c1d280> Application
schneider-electric ecostruxure_power_monitoring_expert 7.0 <built-in method update of dict object at 0x7e6111c1ed40> Application
schneider-electric ecostruxure_power_monitoring_expert 8.0 <built-in method update of dict object at 0x7e6108406a00> Application
schneider-electric ecostruxure_power_monitoring_expert 9.0 <built-in method update of dict object at 0x7e61114e3440> Application
schneider-electric power_manager 1.1 <built-in method update of dict object at 0x7e60a88ac500> Application
schneider-electric power_manager 1.2 <built-in method update of dict object at 0x7e60a88af0c0> Application
schneider-electric power_manager 1.3 <built-in method update of dict object at 0x7e60e8c7c780> Application
schneider-electric powerscada_expert_with_advanced_reporting_and_dashboards 8.0 <built-in method update of dict object at 0x7e60eb226d00> Application
schneider-electric powerscada_operation_with_advanced_reporting_and_dashboards 9.0 <built-in method update of dict object at 0x7e60eb2261c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_energy_expert:2.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:power_manager:1.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:power_manager:1.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:power_manager:1.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:powerscada_expert_with_advanced_reporting_and_dashboards:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:powerscada_operation_with_advanced_reporting_and_dashboards:9.0:*:*:*:*:*:*:*

References

Notification
Message here