7.5
CVSSv2

CVE-2020-7487

Published: 22/04/2020 Updated: 03/02/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the malicious user to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric ecostruxure machine expert

schneider-electric somachine

schneider-electric somachine motion

schneider-electric modicon_m218_firmware

schneider-electric modicon_m241_firmware

schneider-electric modicon_m251_firmware

schneider-electric modicon_m258_firmware