Vulnerabilities (CVE)

Filtered by vendor Schneider-electric Subscribe
Filtered by product Easergy T300
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28215 1 Schneider-electric 2 Easergy T300, Easergy T300 Firmware 2020-12-14 7.5 HIGH 9.8 CRITICAL
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
CVE-2020-7561 1 Schneider-electric 2 Easergy T300, Easergy T300 Firmware 2020-12-11 7.5 HIGH 9.8 CRITICAL
A CWE-284: Improper Access Control vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly restricted.
CVE-2020-7512 1 Schneider-electric 2 Easergy T300, Easergy T300 Firmware 2020-06-19 7.5 HIGH 9.8 CRITICAL
A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to exploit the component.
CVE-2020-7508 1 Schneider-electric 2 Easergy T300, Easergy T300 Firmware 2020-06-17 5.0 MEDIUM 9.8 CRITICAL
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.