Injection Vulnerability in EcoStruxure Machine Expert and SoMachine Basic Software by Schneider Electric
CVE-2020-7489
Key Information:
Summary
A vulnerability exists in EcoStruxure Machine Expert and SoMachine Basic programming software due to improper handling of special output elements. This flaw could allow an attacker to perform DLL substitution, enabling the transfer of malicious code to the controller. This risk emphasizes the importance of ensuring safe coding practices and robust security measures within software implementations.
Affected Version(s)
SoMachine Basic (all )EcoStruxure Machine Expert – Basic (all )Modicon M100 Logic Controller (all )Modicon M200 Logic Controller (all )Modicon M221 Logic Controller (all ) SoMachine Basic (all versions)EcoStruxure Machine Expert – Basic (all versions)Modicon M100 Logic Controller (all versions)Modicon M200 Logic Controller (all versions)Modicon M221 Logic Controller (all versions)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved