Injection Vulnerability in EcoStruxure Machine Expert and SoMachine Basic Software by Schneider Electric
CVE-2020-7489

9.8CRITICAL

Summary

A vulnerability exists in EcoStruxure Machine Expert and SoMachine Basic programming software due to improper handling of special output elements. This flaw could allow an attacker to perform DLL substitution, enabling the transfer of malicious code to the controller. This risk emphasizes the importance of ensuring safe coding practices and robust security measures within software implementations.

Affected Version(s)

SoMachine Basic (all )EcoStruxure Machine Expert – Basic (all )Modicon M100 Logic Controller (all )Modicon M200 Logic Controller (all )Modicon M221 Logic Controller (all ) SoMachine Basic (all versions)EcoStruxure Machine Expert – Basic (all versions)Modicon M100 Logic Controller (all versions)Modicon M200 Logic Controller (all versions)Modicon M221 Logic Controller (all versions)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.