CVE-2020-7528

HIGH

Schneider-electric Scadapack 7X Remot... - Insecure Deserialization

Title source: rule

Description

A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.

Scores

CVSS v3 7.8
EPSS 0.0041
EPSS Percentile 60.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

schneider-electric/scadapack_7x_remote_connect < 3.6.3.574

Timeline

Published Sep 16, 2020
Tracked Since Feb 18, 2026