CVE-2020-7501

HIGH

Vijeo Designer Basic < 1.1 HotFix 16 and Vijeo Designer < 6.2 SP9 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (4)
schneider-electric/vijeo_designer 1.1 (2 CPE variants)
schneider-electric/vijeo_designer 6.9 (2 CPE variants)
schneider-electric/vijeo_designer < 1.0
schneider-electric/vijeo_designer < 6.2
Published Jun 16, 2020
Tracked Since Feb 18, 2026