Vulnerability Description
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M258 Firmware | < 5.0.4.11 |
| Schneider-Electric | Modicon M258 | - |
| Schneider-Electric | Somachine | All versions |
| Schneider-Electric | Somachine Motion | All versions |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2020-343-09/Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-343-09/Vendor Advisory
FAQ
What is CVE-2020-28220?
CVE-2020-28220 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion softwa...
How severe is CVE-2020-28220?
CVE-2020-28220 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28220?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M258 Firmware, Schneider-Electric Modicon M258, Schneider-Electric Somachine, Schneider-Electric Somachine Motion.