Hard-coded Credentials Vulnerability in Vijeo Designer by Schneider Electric
CVE-2020-7501
8.8HIGH
Summary
A vulnerability exists in Schneider Electric's Vijeo Designer Basic and Vijeo Designer products that allows malicious actors to exploit hard-coded credentials. This security flaw enables unauthorized read and write access during the upload and download of project files or firmware, posing a significant risk to the integrity and confidentiality of systems using this software.
Affected Version(s)
Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior)
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved