CVE-2020-7474
 
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL.
Una CWE-427: Se presenta una vulnerabilidad de Elemento de Ruta de Búsqueda No Controlada en ProSoft Configurator (versiones v1.002 y anteriores), para el módulo PMEPXM0100 (H), que podría causar la ejecución de código no confiable cuando se usa un doble clic para abrir un archivo de proyecto que puede desencadenar en una ejecución de una DLL maliciosa.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-01-21 CVE Reserved
- 2020-03-23 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-042-01 | 2020-03-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Pmepxm0100 Prosoft Configurator Search vendor "Schneider-electric" for product "Pmepxm0100 Prosoft Configurator" | <= 1.002 Search vendor "Schneider-electric" for product "Pmepxm0100 Prosoft Configurator" and version " <= 1.002" | - |
Affected
|