CVE-2020-7495: Path Traversal
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7495?
CVE-2020-7495 is a vulnerability in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior that allows unauthorized write access outside of the expected directory during zip file extraction.
How severe is CVE-2020-7495?
CVE-2020-7495 has a severity rating of medium (5.5).
Which software versions are affected by CVE-2020-7495?
EcoStruxure Operator Terminal Expert versions 3.0, 3.1, and 3.1 Service Pack 1 (3.1-sp1) are affected by CVE-2020-7495.
How can I fix CVE-2020-7495?
To fix CVE-2020-7495, it is recommended to upgrade to EcoStruxure Operator Terminal Expert version 3.1 Service Pack 2 or later.
Where can I find more information about CVE-2020-7495?
You can find more information about CVE-2020-7495 at the following link: https://www.se.com/ww/en/download/document/SEVD-2020-133-04