CRITICAL🇵🇱 Wersja polska

CVE-2020-28212

CVSS 9.8v3.1pub. 2020-11-19upd. 2024-11-21

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Schneider Electric Ecostruxure Control Expert

    APP
    Schneider-Electric
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-37300CRITICAL9.8PL ✓same product

Słaby mechanizm odzyskiwania hasła w produktach Schneider Electric — dostęp przez Modbus

CVE-2022-26507CRITICAL9.8PL ✓same product

Heap-based buffer overflow w AT&T Xmill — możliwe zdalne wykonanie kodu

CVE-2021-22779CRITICAL9.1PL ✓same product

Authentication Bypass w produktach Schneider Electric via Modbus Spoofing

CVE-2020-7475CRITICAL9.8PL ✓same product

Injection (reflective DLL) w produktach Schneider Electric — przesyłanie złośliwego kodu do sterownika

CVE-2023-27975HIGH7.1same product

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to th...