CVE-2020-7561
Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly restricted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authentication in Schneider Electric Easergy T300 (firmware ≤2.7) allows remote attackers to execute arbitrary code, cause denial of service, or expose sensitive information.
Vulnerability
The Easergy T300 product from Schneider Electric, running firmware versions 2.7 and prior, contains a missing authentication for critical function vulnerability (CWE-306) [1]. This flaw allows an attacker to access resources without proper authentication, leading to potential information exposure, denial of service, and remote code execution.
Exploitation
An attacker can exploit this vulnerability remotely over the network without any authentication or user interaction [1]. The CVSS vector string (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H) indicates low attack complexity and no privileges required. By sending crafted requests to the affected device, an attacker can bypass authentication checks and interact with critical functions.
Impact
Successful exploitation grants the attacker unauthorized access to the internal product LAN, enabling exposure of sensitive information, denial of service, and remote code execution [1]. The scope of impact is changed, meaning the compromise can affect resources beyond the vulnerable component.
Mitigation
As of the advisory publication date (November 2020), no firmware update has been released to address CVE-2020-7561 [1]. Users are advised to follow the mitigations recommended in the CISA advisory, such as network segmentation, firewall rules, and restricting access to trusted networks. Contact Schneider Electric for further guidance.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Easergy/Easergy T300description
- Range: <= firmware 2.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.