Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:schneider-electric:ecostruxure_energy_expert:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "CDF7DFC6-6F41-491B-A703-6AB0143FE5B1", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0:*:*:*:*:*:*:*", "matchCriteriaId": "6819EA7A-C803-480F-98DF-44DA144FE488", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0:*:*:*:*:*:*:*", "matchCriteriaId": "66E928C4-87C8-4BD6-9131-B7D558330CBA", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0:*:*:*:*:*:*:*", "matchCriteriaId": "0BEB4F4B-0B22-47CA-B173-C06C1A925348", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:power_manager:1.1:*:*:*:*:*:*:*", "matchCriteriaId": "2FC0093C-00CE-43A8-80EC-0509992E637B", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:power_manager:1.2:*:*:*:*:*:*:*", "matchCriteriaId": "CE9A1DF0-42B8-4123-8276-1D4BED156034", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:power_manager:1.3:*:*:*:*:*:*:*", "matchCriteriaId": "54A54A8D-40F5-4E75-A524-B81E487DB274", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:powerscada_expert_with_advanced_reporting_and_dashboards:8.0:*:*:*:*:*:*:*", "matchCriteriaId": "3CC2CF9D-8D0C-4FD3-94A2-34A63E297B81", "vulnerable": true}, {"criteria": "cpe:2.3:a:schneider-electric:powerscada_operation_with_advanced_reporting_and_dashboards:9.0:*:*:*:*:*:*:*", "matchCriteriaId": "DC8F406C-868A-443C-8842-6CFFFF17C236", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxure\u00aa and SmartStruxure\u00aa Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an affected webpage."}, {"lang": "es", "value": "Una CWE-79: Se presenta una vulnerabilidad Neutralizaci\u00f3n Inapropiada de la Entrada Durante la Generaci\u00f3n de P\u00e1ginas Web en el Software EcoStruxure\u00aa y SmartStruxure\u00aa Power Monitoring and SCADA (v\u00e9ase la notificaci\u00f3n de seguridad para la informaci\u00f3n de la versi\u00f3n) que podr\u00eda permitir a un atacante llevar a cabo acciones en nombre del usuario autorizado cuando se acceder a un p\u00e1gina web afectada"}], "id": "CVE-2020-7546", "lastModified": "2024-11-21T05:37:21.363", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "LOW", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "NONE", "baseScore": 3.5, "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "version": "2.0"}, "exploitabilityScore": 6.8, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}], "cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.4, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "version": "3.1"}, "exploitabilityScore": 2.3, "impactScore": 2.7, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2020-12-01T15:15:12.563", "references": [{"source": "cybersecurity@se.com", "tags": ["Vendor Advisory"], "url": "https://www.se.com/ww/en/download/document/SEVD-2020-287-04/"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://www.se.com/ww/en/download/document/SEVD-2020-287-04/"}], "sourceIdentifier": "cybersecurity@se.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-79"}], "source": "cybersecurity@se.com", "type": "Secondary"}]}