#VU48962 Write-what-where Condition in EcoStruxure Control Expert - CVE-2020-7560
Published: December 11, 2020 / Updated: December 14, 2020
EcoStruxure Control Expert
Schneider Electric
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a write-what-where condition in the APX project file processing functionality. A remote attacker can trick a victim to open a STA project archive containing a specially crafted APX project file and execute arbitrary code on the target system.