CWE
119
Advisory Published
Updated

CVE-2020-28220: Buffer Overflow

First published: Fri Dec 11 2020(Updated: )

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.

Credit: cybersecurity@se.com

Affected SoftwareAffected VersionHow to fix
Schneider-electric Modicon M258 Firmware<5.0.4.11
Schneider-electric Modicon M258
Schneider-electric Somachine
Schneider-electric Somachine Motion

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-28220?

    CVE-2020-28220 is a memory buffer vulnerability that exists in Modicon M258 Firmware and SoMachine/SoMachine Motion software.

  • What is the severity of CVE-2020-28220?

    The severity of CVE-2020-28220 is medium with a CVSS score of 6.8.

  • Which software versions are affected by CVE-2020-28220?

    All versions of Modicon M258 Firmware prior to V5.0.4.11 and all versions of SoMachine/SoMachine Motion software are affected by CVE-2020-28220.

  • How can CVE-2020-28220 be exploited?

    CVE-2020-28220 can be exploited by causing a buffer overflow when transferring a file to the vulnerable software.

  • How can I fix CVE-2020-28220?

    To fix CVE-2020-28220, it is recommended to update Modicon M258 Firmware to version 5.0.4.11 or later, and update SoMachine/SoMachine Motion software to the latest version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203