Unrated severityNVD Advisory· Published Apr 22, 2020· Updated Aug 4, 2024
CVE-2020-7489
CVE-2020-7489
Description
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.
Affected products
2- Schneider Electric/EcoStruxure Machine Expert – Basic or SoMachine Basic programming softwaredescription
- Range: versions in security notification
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.se.com/ww/en/download/document/SEVD-2020-105-01mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.