ID

VAR-202012-0819


CVE

CVE-2020-28219


TITLE

EcoStruxure Geo SCADA Expert 2019  and  2020  Vulnerability regarding inadequate protection of credentials in

Trust: 0.8

sources: JVNDB: JVNDB-2020-014611

DESCRIPTION

A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX. EcoStruxure Geo SCADA Expert 2019 and 2020 Exists in an inadequate protection of credentials.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2020-28219 // JVNDB: JVNDB-2020-014611

AFFECTED PRODUCTS

vendor:schneider electricmodel:ecostruxure geo scada expert 2019scope:gteversion:81.7268.1

Trust: 1.0

vendor:schneider electricmodel:ecostruxure geo scada expert 2019scope:lteversion:81.7578.1

Trust: 1.0

vendor:schneider electricmodel:ecostruxure geo scada expert 2020scope:gteversion:83.7551.1

Trust: 1.0

vendor:schneider electricmodel:ecostruxure geo scada expert 2020scope:lteversion:83.7578.1

Trust: 1.0

vendor:schneider electricmodel:ecostruxure geo scada expert 2019scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:ecostruxure geo scada expert 2020scope:eqversion:original release monthly updates to september 2020, to 83.7551.1 to 83.7578.1

Trust: 0.8

sources: JVNDB: JVNDB-2020-014611 // NVD: CVE-2020-28219

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-28219
value: HIGH

Trust: 1.0

NVD: CVE-2020-28219
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202012-937
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-28219
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2020-28219
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2020-28219
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-014611 // CNNVD: CNNVD-202012-937 // NVD: CVE-2020-28219

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.0

problemtype:Inadequate protection of credentials (CWE-522) [ Other ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-014611 // NVD: CVE-2020-28219

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202012-937

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202012-937

PATCH

title:SEVD-2020-343-02url:https://www.se.com/ww/en/download/document/SEVD-2020-343-02/

Trust: 0.8

title:Schneider Electric EcoStruxure Geo SCADA Expert Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=137442

Trust: 0.6

sources: JVNDB: JVNDB-2020-014611 // CNNVD: CNNVD-202012-937

EXTERNAL IDS

db:NVDid:CVE-2020-28219

Trust: 2.4

db:SCHNEIDERid:SEVD-2020-343-02

Trust: 1.6

db:JVNDBid:JVNDB-2020-014611

Trust: 0.8

db:CNNVDid:CNNVD-202012-937

Trust: 0.6

sources: JVNDB: JVNDB-2020-014611 // CNNVD: CNNVD-202012-937 // NVD: CVE-2020-28219

REFERENCES

url:https://www.se.com/ww/en/download/document/sevd-2020-343-02/

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-28219

Trust: 0.8

sources: JVNDB: JVNDB-2020-014611 // CNNVD: CNNVD-202012-937 // NVD: CVE-2020-28219

SOURCES

db:JVNDBid:JVNDB-2020-014611
db:CNNVDid:CNNVD-202012-937
db:NVDid:CVE-2020-28219

LAST UPDATE DATE

2024-11-23T22:47:48.423000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-014611date:2021-08-26T06:08:00
db:CNNVDid:CNNVD-202012-937date:2020-12-17T00:00:00
db:NVDid:CVE-2020-28219date:2024-11-21T05:22:29.843

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-014611date:2021-08-26T00:00:00
db:CNNVDid:CNNVD-202012-937date:2020-12-11T00:00:00
db:NVDid:CVE-2020-28219date:2020-12-11T01:15:11.860