VendorsSchneider Electriceasergy_builderall versions
Vulnerabilities

Schneider Electric Schneider-Electric Easergy Builder

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-7515
A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker to decrypt a password.
Published 2020-07-23 · Modified
7.8EPSS 0.003
CVE-2020-7514
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to the authorization credentials for a device and gain full access.
Published 2020-07-23 · Modified
7.8EPSS 0.002
CVE-2020-7516
A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker access to login credentials.
Published 2020-07-23 · Modified
7.8EPSS 0.002
CVE-2020-7519
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
Published 2020-07-23 · Modified
7.5EPSS 0.013
CVE-2020-7518
A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.
Published 2020-07-23 · Modified
7.5EPSS 0.011
CVE-2020-7517
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to read user credentials.
Published 2020-07-23 · Modified
5.5EPSS 0.002