7.5
CVSSv2

CVE-2020-7489

Published: 22/04/2020 Updated: 31/01/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric ecostruxure machine expert

schneider-electric somachine basic

schneider-electric modicon_m100_firmware

schneider-electric modicon_m200_firmware

schneider-electric modicon_m221_firmware