CVE-2020-7475: Critical severity Schneider-electric Ecostruxure Control Expert vulnerability
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EcoStruxure Control Expertto a version that resolves this vulnerability.Fixed in 14.1 Hot Fix - Upgrade
Upgrade
Modicon M340to a version that resolves this vulnerability.Fixed in V3.20 - Upgrade
Upgrade
Modicon M580to a version that resolves this vulnerability.Fixed in V3.10
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-7475.
What is the severity of CVE-2020-7475?
The severity of CVE-2020-7475 is critical with a severity value of 9.8.
Which software versions are affected by CVE-2020-7475?
EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10) are affected by CVE-2020-7475.
What is the CWE-ID of CVE-2020-7475?
The CWE-ID of CVE-2020-7475 is CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection').
How can I fix CVE-2020-7475?
To fix CVE-2020-7475, update EcoStruxure Control Expert to version 14.1 Hot Fix or later, update Unity Pro to the latest version, update Modicon M340 to V3.20 or later, and update Modicon M580 to V3.10 or later.