← Retour aux CVEs
CVE-2020-7568
MEDIUM4.3
Description
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all references, all versions) that could allow non sensitive information disclosure when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.
Details CVE
Score CVSS v3.14.3
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie11/19/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
schneider-electric:modicon_m221schneider-electric:modicon_m221_firmware
Faiblesses (CWE)
CWE-200
References
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-04(cybersecurity@se.com)
https://www.se.com/ww/en/download/document/SEVD-2020-315-05/(cybersecurity@se.com)
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-04(af854a3a-2127-422b-91ae-364da2661108)
https://www.se.com/ww/en/download/document/SEVD-2020-315-05/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.