LiveActive security incident?Get immediate response
CVE Record

CVE-2020-7561: A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware...

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly restricted.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Easergy T300 devices running firmware 2.7 or older may allow critical functions to be reached without proper authentication. In a utility or industrial environment, that could expose information, disrupt operations, or allow command execution if an attacker can access the affected resource.

Executive priority

Treat this as high priority for utilities or industrial sites running Easergy T300. The issue affects authentication around critical functions and can impact confidentiality, availability, and command integrity, but source evidence is incomplete on exploitation and fixes.

Technical view

CVE-2020-7561 is described as missing authentication for a critical function in Schneider Electric Easergy T300 firmware 2.7 and older. The source bundle cites possible information exposure, denial of service, and command execution when access controls are absent or incorrectly enforced.

Likely exposure

Exposure is limited to environments using Easergy T300 with firmware 2.7 or older. Risk depends on whether affected resources are reachable from untrusted, corporate, remote-access, or OT network paths.

Exploitation context

The bundle does not cite known active exploitation, and KEV status is false. No public exploit status, CVSS vector, or detailed attack preconditions are provided in the supplied sources.

Researcher notes

The provided CVE text names CWE-306, while the bundle CWE list contains CWE-284. Preserve that discrepancy in tracking notes. Avoid exploit testing; focus on asset identification, firmware confirmation, reachability, and vendor-advisory remediation status.

Mitigation direction

  • Review Schneider Electric SEVD-2020-315-06 for supported remediation guidance.
  • Review CISA ICSA-20-343-03 for operational guidance and affected scope.
  • Inventory Easergy T300 devices and identify firmware 2.7 or older.
  • Apply only Schneider- or CISA-recommended fixes or compensating controls.
  • Track remediation as an OT operational-risk item until verified closed.

Validation and detection

  • Confirm whether Easergy T300 devices exist in the OT asset inventory.
  • Record firmware versions and flag firmware 2.7 or older.
  • Verify affected resources are not reachable from untrusted network paths.
  • Check whether Schneider or CISA remediation guidance has been implemented.
  • Document residual exposure where firmware or compensating controls remain unresolved.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-7561 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aEasergy T300 with firmware 2.7 and olderEasergy T300 with firmware 2.7 and olderListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-284 · source CWE mapping

Improper Access Control

Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.