Buffer Overflow Vulnerability in EcoStruxure Control Expert by Schneider Electric
CVE-2020-7559
7.5HIGH
What is CVE-2020-7559?
A buffer overflow vulnerability exists in the PLC Simulator component of EcoStruxure Control Expert, formerly known as Unity Pro. This flaw can be exploited by sending specially crafted requests over the Modbus protocol, potentially leading to a crash of the PLC simulator. It highlights the importance of careful input size validation to prevent unexpected behavior and system instability.
Affected Version(s)
PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all ) PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions)