VDB
SEVD-2020-287-04
SEVD-2020-287-04
PUBLISHED
CVSS 8.399999618530273 HIGH
Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ and SmartStruxure™ Power Monitoring & SCADA Software. Failure to apply the mitigation provided below may risk remote code execution, which could result in an attacker gaining root level access to the underlying operating system on the impacted server.
Risk Scores
CVSS v3.1
8.399999618530273
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider Electric EcoStruxure™ Power SCADA Operations with Advanced Reporting and Dashboard Module Products version 2020 | ||
| Schneider Electric Power Manager version 1.2 | ||
| Schneider Electric Power Manager version 1.1 | ||
| Schneider Electric EcoStruxure™ Power Monitoring Expert version 8.x | ||
| Schneider Electric EcoStruxure™ Power Monitoring Expert version 7.x | ||
| Schneider Electric EcoStruxure™ Power SCADA Operation with Advanced Reporting and Dashboards Module version 9.0 | ||
| Schneider Electric StruxureWare™ PowerSCADA Expert with Advanced Reporting and Dashboards Module version 8.x | ||
| Schneider Electric EcoStruxure™ Power Monitoring Expert Version 2020 | ||
| Schneider Electric EcoStruxure™ Energy Expert version 3.0 | ||
| Schneider Electric EcoStruxure™ Power Monitoring Expert version 9.0 | ||
| Schneider Electric Power Manager version 1.3 | ||
| Schneider Electric EcoStruxure™ Energy Expert version 2.0 |
Timeline
- Oct 13, 2020 CVE Published
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2020-287-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2020-287-04_EcoStruxure_and_SmartStruxure_Power_Monitoring_and_SCADA%20Software_Security_Notification.pdf advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2020-287-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2020-287-04.json advisory
- https://www.se.com/us/en/download/document/7EN52-0390/ url
- https://www.se.com/us/en/work/support/ fix