Security readout for executives and security teams
Plain-English summary
Easergy T300 devices running firmware 2.7 or older may allow critical functions to be reached without proper authentication. In a utility or industrial environment, that could expose information, disrupt operations, or allow command execution if an attacker can access the affected resource.
Executive priority
Treat this as high priority for utilities or industrial sites running Easergy T300. The issue affects authentication around critical functions and can impact confidentiality, availability, and command integrity, but source evidence is incomplete on exploitation and fixes.
Technical view
CVE-2020-7561 is described as missing authentication for a critical function in Schneider Electric Easergy T300 firmware 2.7 and older. The source bundle cites possible information exposure, denial of service, and command execution when access controls are absent or incorrectly enforced.
Likely exposure
Exposure is limited to environments using Easergy T300 with firmware 2.7 or older. Risk depends on whether affected resources are reachable from untrusted, corporate, remote-access, or OT network paths.
Exploitation context
The bundle does not cite known active exploitation, and KEV status is false. No public exploit status, CVSS vector, or detailed attack preconditions are provided in the supplied sources.
Researcher notes
The provided CVE text names CWE-306, while the bundle CWE list contains CWE-284. Preserve that discrepancy in tracking notes. Avoid exploit testing; focus on asset identification, firmware confirmation, reachability, and vendor-advisory remediation status.
Mitigation direction
- Review Schneider Electric SEVD-2020-315-06 for supported remediation guidance.
- Review CISA ICSA-20-343-03 for operational guidance and affected scope.
- Inventory Easergy T300 devices and identify firmware 2.7 or older.
- Apply only Schneider- or CISA-recommended fixes or compensating controls.
- Track remediation as an OT operational-risk item until verified closed.
Validation and detection
- Confirm whether Easergy T300 devices exist in the OT asset inventory.
- Record firmware versions and flag firmware 2.7 or older.
- Verify affected resources are not reachable from untrusted network paths.
- Check whether Schneider or CISA remediation guidance has been implemented.
- Document residual exposure where firmware or compensating controls remain unresolved.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-284: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2020-7561 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.se.com/ww/en/download/document/SEVD-2020-315-06/CVE reference
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-03CVE reference
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Improper Access Control
Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
