CVE-2020-7474
HIGHSchneider-electric Pmepxm0100 Prosoft... - Uncontrolled Search Path
Title source: ruleDescription
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL.
Scores
CVSS v3
7.8
EPSS
0.0015
EPSS Percentile
36.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
schneider-electric/pmepxm0100_prosoft_configurator
< 1.002
Timeline
Published
Mar 23, 2020
Tracked Since
Feb 18, 2026