VYPR

Easergy T300 Firmware

by Schneider Electric

CVEs (24)

  • CVE-2020-28218MedDec 11, 2020
    risk 0.42cvss 6.5epss 0.01

    A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.

  • CVE-2020-25180MedMar 18, 2022
    risk 0.35cvss 5.3epss 0.01

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny…

  • CVE-2020-7504MedJun 16, 2020
    risk 0.35cvss 5.3epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable the webserver service on the device when specially crafted network packets are sent.

  • CVE-2021-22769MedJun 11, 2021
    risk 0.28cvss 4.3epss 0.01

    A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.

Page 2 of 2