Medium severity6.8NVD Advisory· Published Dec 11, 2020· Updated Jun 17, 2026
CVE-2020-28220
CVE-2020-28220
Description
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.
Affected products
6- Modicon/Modicon M258 Firmwaredescription
<V5.0.4.11+ 1 more
- (no CPE)range: <V5.0.4.11
- cpe:2.3:o:schneider-electric:modicon_m258_firmware:*:*:*:*:*:*:*:*range: <5.0.4.11
- Range: All versions
- cpe:2.3:a:schneider-electric:somachine:*:*:*:*:*:*:*:*
- cpe:2.3:a:schneider-electric:somachine_motion:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- www.se.com/ww/en/download/document/SEVD-2020-343-09/nvdVendor Advisory
News mentions
0No linked articles in our index yet.