CVE-2020-7493: SQL Injection
Published Jun 16, 2020
·Updated
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
Affected Software
3 affected components
Schneider-electric Ecostruxure Operator Terminal Expert<=3.0
Schneider-electric Ecostruxure Operator Terminal Expert=3.1
Schneider-electric Ecostruxure Operator Terminal Expert=3.1-sp1
Event History
Jun 16, 2020
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-7493.
2
What is the severity of CVE-2020-7493?
The severity of CVE-2020-7493 is high with a score of 7.8.
3
What is the CWE of CVE-2020-7493?
The CWE of CVE-2020-7493 is CWE-89.
4
Which software versions are affected by CVE-2020-7493?
EcoStruxure Operator Terminal Expert 3.0, 3.1, and 3.1 Service Pack 1 are affected by CVE-2020-7493.
5
How can I fix CVE-2020-7493?
To fix CVE-2020-7493, it is recommended to update EcoStruxure Operator Terminal Expert to the latest version available.