Vulnerability Details CVE-2020-7491
**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-7491
-
cpe:2.3:h:schneider-electric:tricon_tcm_4351:-
-
cpe:2.3:h:schneider-electric:tricon_tcm_4351a:-
-
cpe:2.3:h:schneider-electric:tricon_tcm_4351b:-
-
cpe:2.3:h:schneider-electric:tricon_tcm_4352:-
-
cpe:2.3:h:schneider-electric:tricon_tcm_4352a:-
-
cpe:2.3:h:schneider-electric:tricon_tcm_4352b:-
-
cpe:2.3:h:schneider-electric:tristation_1131:-
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:10.2.0
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:10.3.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351_firmware:10.4.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:10.2.0
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:10.3.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351a_firmware:10.4.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:10.2.0
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:10.3.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4351b_firmware:10.4.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:10.2.0
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:10.3.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352_firmware:10.4.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:10.2.0
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:10.3.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352a_firmware:10.4.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:10.2.0
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:10.3.x
-
cpe:2.3:o:schneider-electric:tricon_tcm_4352b_firmware:10.4.x
-
cpe:2.3:o:schneider-electric:tristation_1131_firmware:1.0.0
-
cpe:2.3:o:schneider-electric:tristation_1131_firmware:4.10.0
-
cpe:2.3:o:schneider-electric:tristation_1131_firmware:4.12.0
-
cpe:2.3:o:schneider-electric:tristation_1131_firmware:4.9.0