CVE-2020-7491
Estado: ModificadaAlta (7.5)—
**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.31%
- Percentil entre todas las CVEs puntuadas: 70
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
Schneider-electric — Tricon TCM 4351 FirmwareSchneider-electric — Tricon TCM 4351a FirmwareSchneider-electric — Tricon TCM 4351b FirmwareSchneider-electric — Tricon TCM 4352 FirmwareSchneider-electric — Tricon TCM 4352a FirmwareSchneider-electric — Tricon TCM 4352b FirmwareSchneider-electric — Tristation 1131 Firmware
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7491",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cybersecurity@se.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Tricon system versions 10.2.0 through 10.5.3",
"versions": [
{
"status": "affected",
"version": "Tricon system versions 10.2.0 through 10.5.3"
}
]
}
]
}
],
"published": "2020-07-23T21:15:12.113",
"references": [
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-205-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cybersecurity@se.com"
},
{
"url": "https://www.se.com/ww/en/download/document/SESB-2020-105-01/",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@se.com"
},
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-205-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.se.com/ww/en/download/document/SESB-2020-105-01/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4."
},
{
"lang": "es",
"value": "**VERSION NO SOPORTADA CUANDO SE ASIGNÓ** Una cuenta de puerto de depuración heredada en los TCM instalados en sistema Tricon versiones 10.2.0 hasta 10.5.3, es visible en la red y podría permitir un acceso inapropiado. Esta vulnerabilidad es corregida en TCM versión 10.5.4"
}
],
"lastModified": "2026-06-17T03:24:53.157",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3183741-92D5-4437-91F6-AF666232204B",
"versionEndExcluding": "10.5.4",
"versionStartIncluding": "10.2.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tricon_tcm_4351:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2CA997CF-D574-4D1B-B71F-A0EBB31303DA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA3F011D-5096-4EF6-94B7-9D66DC29583F",
"versionEndExcluding": "10.5.4",
"versionStartIncluding": "10.2.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tricon_tcm_4352:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1A965FF8-A474-447E-84AE-ED902B47A3A3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8F8AB23-9DA4-4430-9FB1-BCC7D8BB88A9",
"versionEndExcluding": "10.5.4",
"versionStartIncluding": "10.2.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tricon_tcm_4351a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4D4D6502-A5D3-44A9-AF07-6717EADB98D0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F909483-5DEA-4565-96B7-58BC3F0554CE",
"versionEndExcluding": "10.5.4",
"versionStartIncluding": "10.2.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tricon_tcm_4351b:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4A46632D-151C-43D3-BFA3-72C87304AB8B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0AA8E6F5-7D88-403B-B3A2-FB28C5369DF2",
"versionEndExcluding": "10.5.4",
"versionStartIncluding": "10.2.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tricon_tcm_4352a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D4836B8C-1BEC-4076-928D-CBB403836BF2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B069292-3C0B-4CF8-8049-5E45A88FB4CB",
"versionEndExcluding": "10.5.4",
"versionStartIncluding": "10.2.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tricon_tcm_4352b:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "89D4DE85-CC63-415C-9C07-8DE9C762AF3B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:schneider-electric:tristation_1131_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EED15135-BC97-44FD-A2FF-3AEFACB79543",
"versionEndIncluding": "4.9.0",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:o:schneider-electric:tristation_1131_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "016138FC-307D-48D8-87F9-045A8A22498D",
"versionEndIncluding": "4.12.0",
"versionStartIncluding": "4.10.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:schneider-electric:tristation_1131:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "723A226B-0742-4FC7-BF67-C7FA575BC85A"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cybersecurity@se.com"
}