PT-2020-2730 · Schneider Electric · Ecostruxure Operator Terminal Expert
Published
2020-05-13
·
Updated
2020-06-17
·
CVE-2020-7493
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EcoStruxure Operator Terminal Expert versions 3.1 Service Pack 1 and prior
Description
The issue is related to improper handling of VXDZ files and a SQL Injection vulnerability, which could allow an attacker to execute arbitrary code using a specially crafted file or web page. This may lead to malicious code execution when opening a project file.
Recommendations
For EcoStruxure Operator Terminal Expert versions 3.1 Service Pack 1 and prior, update to a version that addresses the improper handling of VXDZ files and the SQL Injection vulnerability to prevent malicious code execution.
As a temporary workaround, consider restricting access to VXDZ files and project files to minimize the risk of exploitation.
Fix
SQL injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ecostruxure Operator Terminal Expert