CVE-2020-7488

EUVD-2020-28613
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
schneider-electricecostruxure_machine_expert
*
schneider-electricsomachine
*
schneider-electricsomachine_motion
*
schneider-electricmodicon_m218_firmware
*
schneider-electricmodicon_m241_firmware
*
schneider-electricmodicon_m251_firmware
*
schneider-electricmodicon_m258_firmware
*
𝑥
= Vulnerable software versions