CVE-2020-7550 – Schneider Electric IGSS CGF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-7550
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 and prior that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. Se presenta una vulnerabilidad de Restricción Inapropiada de Operaciones dentro de los Límites de un Búfer de Memoria CWE-119 en IGSS Definition (Def.exe) versión 14.0.0.20247 y anteriores que podría causar una Ejecución de Código Remota cuando se importa un archivo CGF (Configuration Group File) malicioso a IGSS Definición This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. • https://www.se.com/ww/en/download/document/SEVD-2020-315-03 https://www.zerodayinitiative.com/advisories/ZDI-21-092 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2020-7544
https://notcve.org/view.php?id=CVE-2020-7544
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert. Se presenta una vulnerabilidad de Administración de Privilegios Inapropiado CWE-269 en el tiempo de ejecución de EcoStruxureª Operator Terminal Expert (Vijeo XD) que podría causar una escalada de privilegios en la estación de trabajo al interactuar directamente con un controlador instalado por el software de tiempo de ejecución de EcoStruxureª Operator Terminal Expert • https://www.se.com/ww/en/download/document/SEVD-2020-315-02 • CWE-269: Improper Privilege Management •
CVE-2020-7559
https://notcve.org/view.php?id=CVE-2020-7559
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus. CWE-120: Se presenta una vulnerabilidad de Copia del Búfer sin Comprobar el Tamaño de la Entrada ("Classic Buffer Overflow") en el Simulador de PLC en EcoStruxureª Control Expert (ahora Unity Pro) (todas las versiones) que podría causar un bloqueo del simulador de PLC presente en el software EcoStruxureª Control Expert cuando recibe una petición especialmente diseñada mediante Modbus • https://www.se.com/ww/en/download/document/SEVD-2020-315-07 https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1140 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2020-7538
https://notcve.org/view.php?id=CVE-2020-7538
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus. CWE-754: Se presenta una vulnerabilidad Comprobación Inapropiada de Condiciones Inusuales o Excepcionales en el Simulador de PLC en EcoStruxureª Control Expert (ahora Unity Pro) (todas las versiones) que podría causar un bloqueo del simulador de PLC presente en el software EcoStruxureª Control Expert cuando recibe una petición especialmente diseñada mediante Modbus • https://www.se.com/ww/en/download/document/SEVD-2020-315-07 • CWE-754: Improper Check for Unusual or Exceptional Conditions •
CVE-2020-28213
https://notcve.org/view.php?id=CVE-2020-28213
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus. CWE-494: Se presenta una vulnerabilidad Descarga de Código Sin Comprobación de Integridad en el Simulador de PLC en EcoStruxureª Control Expert (ahora Unity Pro) (todas las versiones) que podría causar la ejecución de comandos no autorizados cuando se envía peticiones especialmente diseñadas mediante Modbus • https://www.se.com/ww/en/download/document/SEVD-2020-315-07 • CWE-494: Download of Code Without Integrity Check •