CyberSec.Space Logo
Back to CVE Browser

CVE-2020-7489

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0030%
EPSS Percentile3.78th
PublishedApr 22, 2020
Last ModifiedMay 28, 2026

Vulnerability Description

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.

Affected Platforms (CPE)

πŸ“¦
Schneider Electric

Ecostruxure Machine Expert

All versions
πŸ“¦
Schneider Electric

Somachine Basic

All versions
πŸ’»
Schneider Electric

Modicon M100 Firmware

All versions
πŸ’»
Schneider Electric

Modicon M200 Firmware

All versions
πŸ’»
Schneider Electric

Modicon M221 Firmware

All versions

References & Advisories

Related Vulnerabilities