VDB
CVE-2020-28213
CVE-2020-28213
PUBLISHED
CVSS 8.800000190734863 HIGH
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.
EPSS 0.35% · 57.7th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.35%
57.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| schneider-electric | ecostruxure_control_expert | |
| n/a | PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) | PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) |
Exploit Intelligence
Timeline
- Nov 12, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://www.se.com/ww/en/download/document/SEVD-2020-315-05/ advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-03/ advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-07/ advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-01/ advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-04/ advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-06/ advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-02/ advisory
- https://www.se.com/ww/en/download/document/SESB-2020-315-01/ advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-07 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-28213 advisory