Download of code without integrity check in Schneider Electric products - CVE-2020-28213
Published: November 19, 2020 / Updated: December 14, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system
The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote authenticated attacker can send specially crafted requests over Modbus and execute arbitrary commands on the target system.
Affected software
PLC Simulator for Unity Pro
EcoStruxure Control Expert