CVE-2020-7573

MEDIUM

EcoStruxure Building Operation WebReports 1.9-3.1 - Improper Access Control

Title source: llm
STIX 2.1

Description

A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control.

References (1)

Core 1
Core References
Patch, Product, Vendor Advisory x_refsource_misc
https://www.se.com/ww/en/download/document/SEVD-2020-315-04/

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-284
Status published
Products (1)
schneider-electric/webreports 1.9 - 3.1
Published Nov 19, 2020
Tracked Since Feb 18, 2026