Missing Encryption Vulnerability in Easergy T300 by Schneider Electric
CVE-2020-28216
7.5HIGH
Summary
A vulnerability exists in Easergy T300 firmware versions up to 2.7, allowing malicious actors to intercept and read sensitive network traffic transmitted over the HTTP protocol. This issue arises from inadequate encryption measures, making data susceptible to unauthorized access. Organizations utilizing the impacted firmware versions should take immediate action to implement stronger encryption protocols to safeguard sensitive information against potential exploitation.
Affected Version(s)
Easergy T300 (firmware 2.7 and older) Easergy T300 (firmware 2.7 and older)
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved