First published: Fri Dec 11 2020(Updated: )
A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious file in EcoStruxure™ Control Expert software.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Control Expert | ||
Schneider-electric Unity Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-7560.
The severity of CVE-2020-7560 is high with a severity value of 8.6.
CVE-2020-7560 affects EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions).
The CWE ID for this vulnerability is CWE-123.
To fix CVE-2020-7560, it is recommended to update EcoStruxure™ Control Expert and Unity Pro to the latest versions available.