CVE Vulnerabilities

CVE-2020-7544

Improper Privilege Management

Published: Nov 19, 2020 | Modified: Jan 31, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Operator_terminal_expert_runtime Schneider-electric * 3.1 (excluding)
Operator_terminal_expert_runtime Schneider-electric 3.1 (including) 3.1 (including)
Operator_terminal_expert_runtime Schneider-electric 3.1-service_pack_1a (including) 3.1-service_pack_1a (including)

Potential Mitigations

References