A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSchneider Electric Ecostruxure Machine Expert
APPSchneider-Electricall versionsSchneider Electric Modicon M100
HWSchneider-Electricall versionsSchneider Electric Modicon M100 Firmware
OSSchneider-Electricall versionsSchneider Electric Modicon M200
HWSchneider-Electricall versionsSchneider Electric Modicon M200 Firmware
OSSchneider-Electricall versionsSchneider Electric Modicon M221
HWSchneider-Electricall versionsSchneider Electric Modicon M221 Firmware
OSSchneider-Electricall versionsSchneider Electric Somachine Basic
APPSchneider-Electricall versions
Related vulnerabilities
Path Traversal w produktach Schneider Electric Harmony HMI via FTP
Niewystarczająca weryfikacja autentyczności danych w sterownikach Schneider Electric Modicon
Replay attack na uwierzytelnianie w Schneider Electric Modicon M221
Nieautoryzowane nadpisanie hasła w Schneider Electric Modicon M221
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause ...