Incorrect Authorization Vulnerability in EcoStruxure Control Expert by Schneider Electric
CVE-2020-28211
7.8HIGH
What is CVE-2020-28211?
An incorrect authorization vulnerability in the PLC Simulator of EcoStruxure Control Expert allows attackers to bypass authentication mechanisms. This vulnerability could be exploited by manipulating memory through the use of a debugger, resulting in unauthorized access to the system. All versions of the product are affected, highlighting the need for immediate attention and remediation to enhance security.
Affected Version(s)
PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all ) PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions)