CVE-2020-7489
EUVD-2020-2861422.04.2020, 19:15
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| schneider-electric | ecostruxure_machine_expert | * |
| schneider-electric | somachine_basic | * |
| schneider-electric | modicon_m100_firmware | * |
| schneider-electric | modicon_m200_firmware | * |
| schneider-electric | modicon_m221_firmware | * |
𝑥
= Vulnerable software versions