Versions
Easergy T300 (firmware 2.7 and older)
Easergy T300 (Firmware version 1.5.2 and older)
Easergy Builder (Version 1.4.7.2 and older)
Schneider Electric PowerLogic 2.651 and older
Lynxspring JENEsys BAS Bridge 1.1.8 and older
Easergy T300 with firmware 2.7 and older
Moxa DACenter 1.4 and older
Easergy T300 with firmware V2.7.1 and older
Recent CVEs
CVE-2021-22771
A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.
CVE-2021-22770
A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensitive information to an actor not explicitly authorized to have access to that information.
CVE-2021-22769
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
CVE-2020-28217
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.