PT-2020-16947 · Schneider Electric · Ecostruxure Control Expert
Published
2020-11-19
·
Updated
2022-01-31
·
CVE-2020-28213
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EcoStruxureª Control Expert (now Unity Pro) (all versions)
Description
A CWE-494: Download of Code Without Integrity Check issue exists in the PLC Simulator that could cause unauthorized command execution when sending specially crafted requests over Modbus.
Recommendations
For all versions, consider restricting access to the Modbus protocol to minimize the risk of exploitation until a patch is available.
As a temporary workaround, consider disabling the PLC Simulator functionality until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Control Expert