9.8
CVE-2020-28215
- EPSS 0.99%
- Veröffentlicht 11.12.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:22:29
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Easergy T300 Firmware Version <= 2.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.99% | 0.748 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.