Improper Access Control Vulnerability in EcoStruxure and SmartStruxure Software by Schneider Electric
CVE-2020-7545
7.2HIGH
What is CVE-2020-7545?
An improper access control vulnerability exists in EcoStruxure and SmartStruxure Power Monitoring and SCADA Software, which may permit an authorized user to execute arbitrary code on the server when accessing specified affected web pages. This flaw poses a significant risk by potentially allowing unauthorized actions on the system, underscoring the importance of strict access controls in safeguarding critical infrastructure.
Affected Version(s)
EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information)