CVE-2020-7488: High severity Schneider-electric Ecostruxure Machine Expert vulnerability
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-7488.
What is the severity level of CVE-2020-7488?
CVE-2020-7488 has a severity level of 7.5 (High).
Which software products are affected by CVE-2020-7488?
The vulnerability affects Schneider-electric Ecostruxure Machine Expert, Schneider-electric Somachine, and Schneider-electric Somachine Motion.
How can CVE-2020-7488 be exploited?
CVE-2020-7488 can be exploited by an attacker intercepting and reading sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.
How can I fix CVE-2020-7488?
To fix CVE-2020-7488, it is recommended to apply the necessary patches and updates provided by Schneider-Electric. Additionally, users should ensure that sensitive information is transmitted securely.