CVE-2020-7544: High severity schneider electric ecostruxure operator terminal expert vulnerability
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7544?
CVE-2020-7544 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2020-7544?
To mitigate CVE-2020-7544, upgrade the EcoStruxure Operator Terminal Expert runtime to version 3.1 Service Pack 1a or higher.
What systems are affected by CVE-2020-7544?
CVE-2020-7544 affects Schneider Electric EcoStruxure Operator Terminal Expert runtime versions up to 3.1.
What type of vulnerability is CVE-2020-7544?
CVE-2020-7544 is an Improper Privilege Management vulnerability that can lead to unauthorized privilege escalation.
Can CVE-2020-7544 be exploited remotely?
CVE-2020-7544 requires direct interaction with the affected software to exploit the privilege escalation.