Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-7523


Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Published

2020-08-31T17:15:12.373

Last Modified

2024-11-21T05:37:18.530

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application schneider-electric modbus_driver_suite < 14.15.0.0 Yes
Application schneider-electric modbus_serial_driver < 2.20_ie_30 Yes
Application schneider-electric modbus_serial_driver < 3.20_ie_30 Yes

References