Known vulnerabilities in EcoStruxure Building Operation WebReports
Vendor:
Schneider Electric
Software CPE:
cpe:2.3:a:schneider_electric:ecostruxure_building_operation_webreports:*:*:*:*:*:*:*:*
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.1
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU51257 - Improper Access Control CVE-2020-7573 |
CWE-284 | Medium | 3.2 | 08.03.2021 |
SB2021030805 |
||
| #VU51256 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2020-7572 |
CWE-611 | Medium | 3.2 | 08.03.2021 |
SB2021030805 |
||
| #VU51255 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-7571 |
CWE-79 | Low | 3.2 | 08.03.2021 |
SB2021030805 |
||
| #VU51254 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-7570 |
CWE-79 | Low | 3.2 | 08.03.2021 |
SB2021030805 |
||
| #VU51253 - Unrestricted Upload of File with Dangerous Type CVE-2020-7569 |
CWE-434 | Medium | 3.2 | 08.03.2021 |
SB2021030805 |