« Volver al listado

CVE-2020-7548

Estado: ModificadaCrítica (9.8)—

A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7548",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@se.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information)",
          "versions": [
            {
              "status": "affected",
              "version": "Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-01T15:15:12.720",
  "references": [
    {
      "url": "https://www.se.com/ww/en/download/document/SEVD-2020-287-03/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cybersecurity@se.com"
    },
    {
      "url": "https://www.se.com/ww/en/download/document/SEVD-2020-287-03/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@se.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-330"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login."
    },
    {
      "lang": "es",
      "value": "Una CWE-330: Se presenta una vulnerabilidad uso de Valores Insuficientemente Aleatorios en Gateways Serie Smartlink, PowerTag y Wiser (véase la notificación de seguridad para la información de la versión) que podría permitir a usuarios no autorizados iniciar sesión"
    }
  ],
  "lastModified": "2026-06-17T03:24:59.213",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:acti9_smartlink_si_d_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53A4A356-8F64-4D1C-8CCB-28803D59BB5B",
              "versionEndExcluding": "002.004.002"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:acti9_smartlink_si_d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B2CA2A7D-C3AB-49BE-B4B8-61177D64B2C8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:acti9_smartlink_si_b_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B72CD29E-2E3E-4E96-A614-355AC1BF348B",
              "versionEndExcluding": "002.004.002"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:acti9_smartlink_si_b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CB18AC59-6752-410B-987F-428D074C9B6A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:acti9_powertag_link_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED821AB9-402E-47E0-9ACB-C7E97653AF28",
              "versionEndExcluding": "001.008.007"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:acti9_powertag_link:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "572B9253-6A4A-456B-B052-A9FB97578BC8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:acti9_powertag_link_hd_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D5E8701-CC1C-423D-BC5F-CB9E586F784A",
              "versionEndExcluding": "001.008.007"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:acti9_powertag_link_hd:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "383B1CB5-BEE7-4387-9B42-925F9F9CC345"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:acti9_smartlink_el_b_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "424EBA8F-CCF4-49A2-8128-94C0D40C50AE",
              "versionEndExcluding": "1.2.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:acti9_smartlink_el_b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1C7D7CC7-F949-4EC4-BCA7-B52CD9FF2524"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:wiser_link_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15224AF4-3090-45CA-9149-0A7C00E4F917",
              "versionEndExcluding": "1.5.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:wiser_link:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "808ED268-575E-49A1-9F0A-C68ADC677A1F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:wiser_energy_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89706F01-2369-4941-B0FA-793B8D828023",
              "versionEndExcluding": "1.5.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:wiser_energy:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "84DAFA0A-0CBF-46B2-BB91-2BD44DF23040"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cybersecurity@se.com"
}