CVE-2020-7545

HIGH

EcoStruxure & SmartStruxure Power Monitoring/SCADA - Authenticated RCE via Web Access

Title source: llm
STIX 2.1

Description

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0046
EPSS Percentile 64.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (9)
schneider-electric/ecostruxure_energy_expert 2.0
schneider-electric/ecostruxure_power_monitoring_expert 7.0
schneider-electric/ecostruxure_power_monitoring_expert 8.0
schneider-electric/ecostruxure_power_monitoring_expert 9.0
schneider-electric/power_manager 1.1
schneider-electric/power_manager 1.2
schneider-electric/power_manager 1.3
schneider-electric/powerscada_expert_with_advanced_reporting_and_dashboards 8.0
schneider-electric/powerscada_operation_with_advanced_reporting_and_dashboards 9.0
Published Dec 01, 2020
Tracked Since Feb 18, 2026