CVE-2020-7501: High severity vijeo designer vulnerability
Published Jun 16, 2020
·Updated
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.
Affected Software
6 affected components
Schneider-electric Vijeo Designer<=1.0
Schneider-electric Vijeo Designer<=6.2
Schneider-electric Vijeo Designer=1.1
Schneider-electric Vijeo Designer=1.1-hotfix_15
Schneider-electric Vijeo Designer=6.9
Schneider-electric Vijeo Designer=6.9-sp9
Event History
Jun 16, 2020
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-7501.
2
What is the severity of CVE-2020-7501?
The severity of CVE-2020-7501 is high.
3
Which software is affected by CVE-2020-7501?
Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) are affected.
4
What is the CWE ID of CVE-2020-7501?
The CWE ID of CVE-2020-7501 is CWE-798.
5
How can unauthorized read and write be caused by CVE-2020-7501?
Unauthorized read and write can occur when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer due to the hard-coded credentials vulnerability.