Critical severity9.8NVD Advisory· Published Apr 22, 2020· Updated Jun 17, 2026
CVE-2020-7489
CVE-2020-7489
Description
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.
Affected products
8- cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*
- cpe:2.3:a:schneider-electric:somachine_basic:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m100_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m200_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m221_firmware:*:*:*:*:*:*:*:*
- Schneider Electric/EcoStruxure Machine Expert – Basic or SoMachine Basic programming softwaredescription
Patches
Vulnerability mechanics
References
1- www.se.com/ww/en/download/document/SEVD-2020-105-01nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.