CVE-2020-7503
HIGHEasergy T300 Firmware < 1.5.2 - Cross-Site Request Forgery via Intercepted XSRF Token
Title source: llmDescription
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.se.com/ww/en/download/document/SEVD-2020-161-04
Scores
CVSS v3
8.8
EPSS
0.0017
EPSS Percentile
37.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (1)
schneider-electric/easergy_t300_firmware
< 1.5.2
Published
Jun 16, 2020
Tracked Since
Feb 18, 2026