CVE-2020-7490

EUVD-2020-28615
A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
schneider-electricvijeo_designer
𝑥
≤ 1.0
schneider-electricvijeo_designer
𝑥
≤ 6.2
schneider-electricvijeo_designer
1.1
schneider-electricvijeo_designer
1.1:hotfix_15
schneider-electricvijeo_designer
6.9
schneider-electricvijeo_designer
6.9:sp9
𝑥
= Vulnerable software versions