VYPR
Unrated severityNVD Advisory· Published Dec 11, 2020· Updated Aug 4, 2024

CVE-2020-28216

CVE-2020-28216

Description

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Easergy T300 firmware versions 2.7 and older transmit sensitive data over unencrypted HTTP, allowing an attacker to read network traffic.

Vulnerability

The Easergy T300 running firmware version 2.7 and earlier transmits sensitive data without encryption over HTTP (CWE-311) [1]. This is one of several findings reported in the CISA advisory ICSA-20-343-03; the same advisory also notes missing authentication for critical functions (CVE-2020-7561) and missing authorization (CVE-2020-28215), but the specific vulnerability covered here is the lack of encryption [1]. No special configuration is required to reach the affected code path; HTTP traffic is the default communication method.

Exploitation

An unauthenticated attacker with network access to the affected device can passively monitor HTTP traffic [1]. No authentication or user interaction is required. The attacker simply positions themselves on the network path between the Easergy T300 and its management peers to capture unencrypted HTTP packets.

Impact

Successful exploitation allows the attacker to read sensitive data transmitted over the network, leading to information disclosure [1]. If the captured traffic contains credentials or other privileged information, the attacker may escalate access to internal systems, potentially resulting in denial of service or remote code execution when combined with the other missing authentication and authorization vulnerabilities reported in the advisory [1].

Mitigation

Schneider Electric has released firmware version 2.8 to address this vulnerability (CVE-2020-28216). Users should update to firmware version 2.8 or later [1]. As a workaround, the advisory recommends network segmentation and restricting access to the affected product’s network interface [1]. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.