CVE-2020-28213: High severity ecostruxure control expert vulnerability
Published Nov 19, 2020
·Updated
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.
Affected Software
1 affected component
Schneider-electric Ecostruxure Control Expert
Remediation
Patch Available
Event History
Nov 19, 2020
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-28213?
CVE-2020-28213 is a Download of Code Without Integrity Check vulnerability that exists in PLC Simulator on EcoStruxure Control Expert (now Unity Pro) that could cause unauthorized command execution.
2
What is the severity of CVE-2020-28213?
The severity of CVE-2020-28213 is high with a CVSS score of 8.8.
3
Which software is affected by CVE-2020-28213?
EcoStruxure Control Expert (now Unity Pro) is affected by CVE-2020-28213.
4
How can CVE-2020-28213 be exploited?
CVE-2020-28213 can be exploited by sending specially crafted requests over Modbus.
5
Is there a fix available for CVE-2020-28213?
Yes, a fix is available. Refer to the vendor's website for more information.