First published: Mon Mar 23 2020(Updated: )
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Control Expert | <=14.0 | |
Schneider-electric Unity Pro | ||
Schneider-electric Modicon M340 Firmware | <3.20 | |
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon M580 Firmware | <3.10 | |
Schneider-electric Modicon M580 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2020-7475.
The severity of CVE-2020-7475 is critical with a severity value of 9.8.
EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), and Modicon M580 (all versions prior to V3.10) are affected by CVE-2020-7475.
The CWE-ID of CVE-2020-7475 is CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection').
To fix CVE-2020-7475, update EcoStruxure Control Expert to version 14.1 Hot Fix or later, update Unity Pro to the latest version, update Modicon M340 to V3.20 or later, and update Modicon M580 to V3.10 or later.