#VU31814 Improper access control in Schneider Electric products - CVE-2020-7491
Published: July 24, 2020
Tricon Communications Module (TCM) Models 4351
Tricon Communications Module (TCM) Models 4352
Tricon Communications Module (TCM) Models 4351A/B
Tricon Communications Module (TCM) Models 4352A/B
Schneider Electric
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in a legacy debug port account. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.
Note: This vulnerability affects the following versions:
- 10.2.0 through 10.5.3