Improper Check for Unusual or Exceptional Conditions in Schneider Electric products - CVE-2020-7538

 

Improper Check for Unusual or Exceptional Conditions in Schneider Electric products - CVE-2020-7538

Published: November 11, 2020


Vulnerability identifier: #VU48363
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7538
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request over Modbus and cause denial of service condition.


Affected software

PLC Simulator for EcoStruxure Control Expert
PLC Simulator for Unity Pro
EcoStruxure Control Expert

How to mitigate CVE-2020-7538

Install updates from vendor's website.

EcoStruxure Control Expert - update to 15.0

External References

Related Security Bulletins