First published: Fri Dec 11 2020(Updated: )
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M258 Firmware | <5.0.4.11 | |
Schneider-electric Modicon M258 | ||
Schneider-electric Somachine | ||
Schneider-electric Somachine Motion |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28220 is a memory buffer vulnerability that exists in Modicon M258 Firmware and SoMachine/SoMachine Motion software.
The severity of CVE-2020-28220 is medium with a CVSS score of 6.8.
All versions of Modicon M258 Firmware prior to V5.0.4.11 and all versions of SoMachine/SoMachine Motion software are affected by CVE-2020-28220.
CVE-2020-28220 can be exploited by causing a buffer overflow when transferring a file to the vulnerable software.
To fix CVE-2020-28220, it is recommended to update Modicon M258 Firmware to version 5.0.4.11 or later, and update SoMachine/SoMachine Motion software to the latest version.