PT-2020-19607 · Schneider Electric · Ecostruxure Machine Expert+1

Published

2020-04-22

·

Updated

2026-05-28

·

CVE-2020-7489

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (affected versions not specified)
Description A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') issue exists, which could result in DLL substitution. This could allow the transference of malicious code to the controller.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2020-7489

Affected Products

Ecostruxure Machine Expert
Somachine Basic