PT-2020-16947 · Schneider Electric · Ecostruxure Control Expert

Published

2020-11-19

·

Updated

2022-01-31

·

CVE-2020-28213

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions EcoStruxureª Control Expert (now Unity Pro) (all versions)
Description A CWE-494: Download of Code Without Integrity Check issue exists in the PLC Simulator that could cause unauthorized command execution when sending specially crafted requests over Modbus.
Recommendations For all versions, consider restricting access to the Modbus protocol to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the PLC Simulator functionality until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28213

Affected Products

Ecostruxure Control Expert