CVE-2020-7560 PUBLISHED CVSS 8.600000381469727 HIGH

A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious file in EcoStruxure™ Control Expert software.

EPSS 0.42% · 61.6th percentile

Risk Scores

CVSS v3.1
8.600000381469727
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score
0.42%
61.6th percentile

Affected Products

VendorProductVersions
schneider-electricunity_pro
n/aEcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions)EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions)
schneider-electricecostruxure_control_expert

Timeline

References

Open in Interactive Console →