Vulnerability Description
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Acti9 Smartlink Si D Firmware | < 002.004.002 |
| Schneider-Electric | Acti9 Smartlink Si D | - |
| Schneider-Electric | Acti9 Smartlink Si B Firmware | < 002.004.002 |
| Schneider-Electric | Acti9 Smartlink Si B | - |
| Schneider-Electric | Acti9 Powertag Link Firmware | < 001.008.007 |
| Schneider-Electric | Acti9 Powertag Link | - |
| Schneider-Electric | Acti9 Powertag Link Hd Firmware | < 001.008.007 |
| Schneider-Electric | Acti9 Powertag Link Hd | - |
| Schneider-Electric | Acti9 Smartlink El B Firmware | < 1.2.1 |
| Schneider-Electric | Acti9 Smartlink El B | - |
| Schneider-Electric | Wiser Link Firmware | < 1.5.0 |
| Schneider-Electric | Wiser Link | - |
| Schneider-Electric | Wiser Energy Firmware | < 1.5.0 |
| Schneider-Electric | Wiser Energy | - |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2020-287-03/PatchVendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-287-03/PatchVendor Advisory
FAQ
What is CVE-2020-7548?
CVE-2020-7548 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized...
How severe is CVE-2020-7548?
CVE-2020-7548 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-7548?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Acti9 Smartlink Si D Firmware, Schneider-Electric Acti9 Smartlink Si D, Schneider-Electric Acti9 Smartlink Si B Firmware, Schneider-Electric Acti9 Smartlink Si B, Schneider-Electric Acti9 Powertag Link Firmware.