First published: Thu Nov 19 2020(Updated: )
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Control Expert |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-7538.
The severity of CVE-2020-7538 is high with a severity value of 7.5.
EcoStruxure Control Expert (now Unity Pro), all versions, is affected by CVE-2020-7538.
The Common Weakness Enumeration (CWE) ID for CVE-2020-7538 is CWE-754.
To fix CVE-2020-7538, apply the necessary patches or updates provided by Schneider-electric for EcoStruxure Control Expert software.