CVE-2020-28213
Summary
| CVE | CVE-2020-28213 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-19 22:15:00 UTC |
| Updated | 2022-01-31 19:33:00 UTC |
| Description | A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Notification - PLC Simulator on EcoStruxure™ Control Expert | Schneider Electric |
MISC |
www.se.com |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590719 Schneider Electric PLC Simulator on EcoStruxure Control Expert and Process Expert Multiple Vulnerabilities (SEVD-2020-315-07)