CVE-2020-7496: High severity schneider electric ecostruxure operator terminal expert vulnerability
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7496?
CVE-2020-7496 is a vulnerability that allows unauthorized write access in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior.
What is the severity of CVE-2020-7496?
The severity of CVE-2020-7496 is high with a CVSS score of 7.8.
How does CVE-2020-7496 work?
CVE-2020-7496 exploits an argument injection or modification vulnerability in EcoStruxure Operator Terminal Expert, allowing unauthorized write access when opening the project file.
What software versions are affected by CVE-2020-7496?
EcoStruxure Operator Terminal Expert versions 3.0, 3.1, and 3.1 Service Pack 1 are affected by CVE-2020-7496.
How can I fix CVE-2020-7496?
To fix CVE-2020-7496, users should update EcoStruxure Operator Terminal Expert to a version that is not affected by the vulnerability.