Download of code without integrity check in Schneider Electric products - CVE-2020-28213
Published: November 19, 2020 / Updated: December 14, 2020
PLC Simulator for EcoStruxure Control Expert
PLC Simulator for Unity Pro
EcoStruxure Control Expert
Schneider Electric
Description
The vulnerability allows a remote attacker to compromise the affected system
The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote authenticated attacker can send specially crafted requests over Modbus and execute arbitrary commands on the target system.