CVE-2020-7485

CRITICAL

TriStation <4.9.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version v4.9.1 and v4.10.1 released on May 30, 2013.1

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-205-01

Scores

CVSS v3 9.8
EPSS 0.0029
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (3)
schneider-electric/tristation_1131 4.10.0
schneider-electric/tristation_1131 4.12.0
schneider-electric/tristation_1131 1.0.0 - 4.9.0
Published Apr 16, 2020
Tracked Since Feb 18, 2026