Vulnerability Description
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Control Expert | All versions |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2020-315-07PatchProductVendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1140ExploitThird Party Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-07PatchProductVendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1140ExploitThird Party Advisory
FAQ
What is CVE-2020-7559?
CVE-2020-7559 is a vulnerability with a CVSS score of 7.5 (HIGH). A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a...
How severe is CVE-2020-7559?
CVE-2020-7559 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7559?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ecostruxure Control Expert.