ID

VAR-202003-1443


CVE

CVE-2020-7477


TITLE

plural Schneider Electric Product Exceptional State Check Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2020-003177

DESCRIPTION

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethernet – 140CPU65xxxxx (all Versions), and Premium processors with integrated Ethernet (all Versions), which could cause a Denial of Service when sending a specially crafted command over Modbus

Trust: 1.62

sources: NVD: CVE-2020-7477 // JVNDB: JVNDB-2020-003177

AFFECTED PRODUCTS

vendor:schneider electricmodel:140cpu65150scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp573634mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu67060scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp57104mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140noe77111scope:lteversion:7.0

Trust: 1.0

vendor:schneider electricmodel:tsxp57204mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp57304mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp572634mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu65260scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu67160sscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu67261scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu65160sscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxh5744mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp576634mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxh5724mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp571634mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp57154mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu67260scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp57254mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu65860scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu67861scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp575634mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp57554mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu65160scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140noe77101scope:lteversion:7.0

Trust: 1.0

vendor:schneider electricmodel:tsxp574634mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140cpu67160scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:tsxp57454mscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:140noe 77101scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:140noe 77111scope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxh5724mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxh5744mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxp 573634 mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxp57454mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxp574634mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxp57554mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxp575634mscope: - version: -

Trust: 0.8

vendor:schneider electricmodel:tsxp576634mscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-003177 // NVD: CVE-2020-7477

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-7477
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-003177
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202003-1339
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-7477
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-003177
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-7477
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-003177
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-003177 // CNNVD: CNNVD-202003-1339 // NVD: CVE-2020-7477

PROBLEMTYPE DATA

problemtype:CWE-754

Trust: 1.8

sources: JVNDB: JVNDB-2020-003177 // NVD: CVE-2020-7477

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202003-1339

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202003-1339

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-003177

PATCH

title:SEVD-2020-070-021url:https://www.se.com/ww/en/download/document/SEVD-2020-070-02/

Trust: 0.8

title:Multiple Schneider Electric Product code issue vulnerability fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=112781

Trust: 0.6

sources: JVNDB: JVNDB-2020-003177 // CNNVD: CNNVD-202003-1339

EXTERNAL IDS

db:NVDid:CVE-2020-7477

Trust: 2.4

db:SCHNEIDERid:SEVD-2020-070-02

Trust: 1.6

db:JVNDBid:JVNDB-2020-003177

Trust: 0.8

db:CNNVDid:CNNVD-202003-1339

Trust: 0.6

sources: JVNDB: JVNDB-2020-003177 // CNNVD: CNNVD-202003-1339 // NVD: CVE-2020-7477

REFERENCES

url:https://www.se.com/ww/en/download/document/sevd-2020-070-02/

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-7477

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-7477\

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-7477

Trust: 0.6

sources: JVNDB: JVNDB-2020-003177 // CNNVD: CNNVD-202003-1339 // NVD: CVE-2020-7477

SOURCES

db:JVNDBid:JVNDB-2020-003177
db:CNNVDid:CNNVD-202003-1339
db:NVDid:CVE-2020-7477

LAST UPDATE DATE

2024-11-23T22:41:08.668000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-003177date:2020-04-07T00:00:00
db:CNNVDid:CNNVD-202003-1339date:2020-04-30T00:00:00
db:NVDid:CVE-2020-7477date:2024-11-21T05:37:13.433

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-003177date:2020-04-07T00:00:00
db:CNNVDid:CNNVD-202003-1339date:2020-03-23T00:00:00
db:NVDid:CVE-2020-7477date:2020-03-23T20:15:12.230