CVE-2020-7476: High severity Schneider-electric Ulti Zigbee Installation Toolkit vulnerability
A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZigBee Installation Kitto a version that resolves this vulnerability.Fixed in 1.0.1
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-7476.
What is the severity of CVE-2020-7476?
The severity of CVE-2020-7476 is high, with a CVSS score of 7.8.
What is the description of CVE-2020-7476?
CVE-2020-7476 is a CWE-426: Untrusted Search Path vulnerability that exists in ZigBee Installation Kit (Versions prior to 1.0.1). It could cause execution of malicious code when a malicious file is put in the search path.
Which software versions are affected by CVE-2020-7476?
Versions prior to 1.0.1 of Schneider-electric Ulti Zigbee Installation Toolkit are affected by CVE-2020-7476.
How can I fix CVE-2020-7476?
To fix CVE-2020-7476, it is recommended to update ZigBee Installation Kit to version 1.0.1 or later.