Description


A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 ((IEC104) SC2-04IEC-07000100 and earlier), and Easergy T200 ((DNP3) SC2-04DNP-07000102 and earlier) that could cause unauthorized operation when authentication is bypassed.

Related CPE's


o

schneider-electric

t200i_firmware

3

h

schneider-electric

t200i

3

o

schneider-electric

t200e_firmware

3

h

schneider-electric

t200e

3

o

schneider-electric

t200p_firmware

3

h

schneider-electric

t200p

3

Weaknesses



CWE-306


CWE-306

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2021-07-21T15:15:15.117

3 years ago

Last modified

2021-07-28T14:35:08.187

3 years ago