A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.
References
Link | Resource |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-287-04/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-12-01 07:15
Updated : 2022-09-02 20:43
NVD link : CVE-2020-7547
Mitre link : CVE-2020-7547
JSON object : View
CWE
Products Affected
schneider-electric
- ecostruxure_power_monitoring_expert
- ecostruxure_energy_expert
- powerscada_operation_with_advanced_reporting_and_dashboards
- powerscada_expert_with_advanced_reporting_and_dashboards
- power_manager