Vulnerability Description
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Control Expert | All versions |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2020-315-07PatchVendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-07PatchVendor Advisory
FAQ
What is CVE-2020-28213?
CVE-2020-28213 is a vulnerability with a CVSS score of 8.8 (HIGH). A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution ...
How severe is CVE-2020-28213?
CVE-2020-28213 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28213?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ecostruxure Control Expert.