CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-7489

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0030%
EPSS Percentile3.78th
Published2020年4月22日
Last Modified2026年5月28日

Vulnerability Description

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.

Affected Platforms (CPE)

📦
Schneider Electric

Ecostruxure Machine Expert

All versions
📦
Schneider Electric

Somachine Basic

All versions
💻
Schneider Electric

Modicon M100 Firmware

All versions
💻
Schneider Electric

Modicon M200 Firmware

All versions
💻
Schneider Electric

Modicon M221 Firmware

All versions

References & Advisories

関連する脆弱性情報