CVE-2020-7538: High severity ecostruxure control expert vulnerability
Published Nov 19, 2020
·Updated
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.
Affected Software
1 affected component
Schneider-electric Ecostruxure Control Expert
Remediation
Patch Available
Event History
Nov 19, 2020
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-7538.
2
What is the severity of CVE-2020-7538?
The severity of CVE-2020-7538 is high with a severity value of 7.5.
3
Which software is affected by CVE-2020-7538?
EcoStruxure Control Expert (now Unity Pro), all versions, is affected by CVE-2020-7538.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-7538?
The Common Weakness Enumeration (CWE) ID for CVE-2020-7538 is CWE-754.
5
How can I fix CVE-2020-7538?
To fix CVE-2020-7538, apply the necessary patches or updates provided by Schneider-electric for EcoStruxure Control Expert software.