VYPR
Unrated severityNVD Advisory· Published Dec 11, 2020· Updated Aug 4, 2024

CVE-2020-28215

CVE-2020-28215

Description

A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Easergy T300 firmware 2.7 and older has missing authorization (CWE-862) that can lead to info disclosure, denial of service, and arbitrary code execution.

Vulnerability

A missing authorization vulnerability (CWE-862) exists in Schneider Electric's Easergy T300 products running firmware versions 2.7 and prior [1]. Access control checks are not consistently applied, allowing an attacker to exploit the missing authorization to reach critical functions. This issue is distinct from the related missing authentication vulnerability (CVE-2020-7561) but shares the same affected product range [1].

Exploitation

An attacker can exploit this vulnerability remotely over the network without requiring authentication [1]. The CVSS vector indicates high attack complexity (AC:H), meaning the attacker may need to overcome some environmental or timing factors, but no privileges or user interaction are needed [1]. The specific steps to trigger the missing authorization condition are not publicly detailed in the available references.

Impact

Successful exploitation allows an attacker to gain unauthorized access to the internal product LAN [1]. This can result in exposure of sensitive information, denial of service, and remote code execution, as the attacker can access resources without proper restriction [1]. The CVSS v3 base score is 7.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H), indicating a high impact on integrity and availability [1].

Mitigation

Schneider Electric has released firmware updates to address this vulnerability. Users should upgrade Easergy T300 to firmware version 2.8 or later [1]. If upgrading is not immediately possible, users should restrict network access to the affected devices as a workaround [1]. This vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.