Vulnerabilities > Schneider Electric > Easergy T300 Firmware > 2.7

DATE CVE VULNERABILITY TITLE RISK
2020-12-11 CVE-2020-28216 Missing Encryption of Sensitive Data vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2/2.7
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
network
low complexity
schneider-electric CWE-311
5.0
2020-12-11 CVE-2020-28215 Missing Authorization vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2/2.7
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
network
low complexity
schneider-electric CWE-862
7.5
2020-11-19 CVE-2020-7561 Improper Access Control vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2/2.7
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly restricted.
network
low complexity
schneider-electric CWE-284
critical
9.8