Download of code without integrity check in Schneider Electric products - CVE-2020-28213

 

Download of code without integrity check in Schneider Electric products - CVE-2020-28213

Published: November 19, 2020 / Updated: December 14, 2020


Vulnerability identifier: #VU48965
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28213
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system

The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote authenticated attacker can send specially crafted requests over Modbus and execute arbitrary commands on the target system. 


Affected software

PLC Simulator for EcoStruxure Control Expert
PLC Simulator for Unity Pro
EcoStruxure Control Expert

How to mitigate CVE-2020-28213

Install updates from vendor's website.

EcoStruxure Control Expert - update to 15.0

External References

Related Security Bulletins