CVE-2020-7487: Critical severity schneider electric ecostruxure machine expert vulnerability
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7487?
CVE-2020-7487 is a vulnerability that allows an attacker to execute malicious code on Modicon M218, M241, M251, and M258 controllers.
Which software is affected by CVE-2020-7487?
CVE-2020-7487 affects Schneider-electric Ecostruxure Machine Expert, Schneider-electric Somachine, and Schneider-electric Somachine Motion.
How severe is CVE-2020-7487?
CVE-2020-7487 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2020-7487?
An attacker can exploit CVE-2020-7487 by leveraging the insufficient verification of data authenticity vulnerability to execute malicious code on the affected controllers.
Is there a fix for CVE-2020-7487?
Schneider-electric has released a security advisory (SEVD-2020-105-02) providing mitigation steps and patches to address CVE-2020-7487.