High severity7.8NVD Advisory· Published Nov 19, 2020· Updated Jun 17, 2026
CVE-2020-7544
CVE-2020-7544
Description
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
Affected products
5- Schneider Electric/EcoStruxureª Operator Terminal Expertdescription
cpe:2.3:a:schneider-electric:operator_terminal_expert_runtime:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:schneider-electric:operator_terminal_expert_runtime:*:*:*:*:*:*:*:*range: <3.1
- cpe:2.3:a:schneider-electric:operator_terminal_expert_runtime:3.1:-:*:*:*:*:*:*
- cpe:2.3:a:schneider-electric:operator_terminal_expert_runtime:3.1:service_pack_1a:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- www.se.com/ww/en/download/document/SEVD-2020-315-02/nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.