CVE-2020-7559

HIGH

Schneider-electric Ecostruxure Control Expert - Buffer Overflow

Title source: rule
STIX 2.1

Description

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.

References (2)

Core 2
Core References
Patch, Product, Vendor Advisory x_refsource_misc
https://www.se.com/ww/en/download/document/SEVD-2020-315-07
Exploit, Third Party Advisory x_refsource_misc
https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1140

Scores

CVSS v3 7.5
EPSS 0.0050
EPSS Percentile 66.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-120
Status published
Products (1)
schneider-electric/ecostruxure_control_expert
Published Nov 19, 2020
Tracked Since Feb 18, 2026