A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSchneider Electric Ecostruxure Control Expert
APPSchneider-Electric≤ 14.0Schneider Electric Modicon M340
HWSchneider-Electricall versionsSchneider Electric Modicon M340 Firmware
OSSchneider-Electric< 3.20Schneider Electric Modicon M580
HWSchneider-Electricall versionsSchneider Electric Modicon M580 Firmware
OSSchneider-Electric< 3.10Schneider Electric Unity Pro
APPSchneider-Electricall versions
Related vulnerabilities
Słaby mechanizm odzyskiwania hasła w produktach Schneider Electric — dostęp przez Modbus
Heap-based buffer overflow w AT&T Xmill — możliwe zdalne wykonanie kodu
Authentication Bypass w produktach Schneider Electric via Modbus Spoofing
Brak limitu prób uwierzytelnienia w PLC Simulator EcoStruxure Control Expert
Nieprawidłowa kontrola dostępu w sterownikach Schneider Electric Modicon via Modbus