Critical severity9.8NVD Advisory· Published Jun 16, 2020· Updated Jun 17, 2026
CVE-2020-7498
CVE-2020-7498
Description
A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is considered a vulnerability, which could cause unauthorized access to the file transfer service provided by the Modicon PLCs. This could result in various unintended results.
Affected products
3- cpe:2.3:a:schneider-electric:os_loader:*:*:*:*:*:*:*:*
- cpe:2.3:a:schneider-electric:unity_loader:*:*:*:*:*:*:*:*
- Range: all versions
Patches
Vulnerability mechanics
References
1- www.se.com/ww/en/download/document/SEVD-2020-161-02nvdVendor Advisory
News mentions
0No linked articles in our index yet.