7.5
CVSSv2

CVE-2020-7475

Published: 23/03/2020 Updated: 03/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions before 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow malicious users to transfer malicious code to the controller.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric ecostruxure control expert

schneider-electric unity pro

schneider-electric modicon_m340_firmware

schneider-electric modicon_m580_firmware