PT-2020-14753 · Schneider Electric · Command Centre

Published

2020-09-15

·

Updated

2020-09-24

·

CVE-2020-16101

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Command Centre versions prior to 8.20.1166(MR3) Command Centre versions prior to 8.10.1211(MR5) Command Centre versions prior to 8.00.1228(MR6) Command Centre versions 7.90 and earlier
Description The issue allows an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access.
Recommendations For versions prior to 8.20.1166(MR3), update to version 8.20.1166(MR3) or later. For versions prior to 8.10.1211(MR5), update to version 8.10.1211(MR5) or later. For versions prior to 8.00.1228(MR6), update to version 8.00.1228(MR6) or later. For versions 7.90 and earlier, update to a version later than 7.90.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-16101

Affected Products

Command Centre