CVE-2020-7495
Schneider Electric EcoStructure Operator Terminal Expert ZIP Path Traversal Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.
Una CWE-22: Se presenta una vulnerabilidad de Limitación Inapropiada de un Nombre de Ruta en un Directorio Restringido ("Path Traversal") durante la extracción de un archivo zip se presenta en EcoStruxure Operator Terminal Expert versiones 3.1 Service Pack 1 y anteriores (anteriormente conocido como Vijeo XD) que podría causar un acceso de escritura no autorizado fuera de la carpeta de ruta esperada cuando se abre el archivo del proyecto
The vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStructure Operator Terminal Expert. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists with the handling of ZIP files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-21 CVE Reserved
- 2020-05-14 CVE Published
- 2024-03-03 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-133-04 | 2020-06-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Operator Terminal Expert Search vendor "Schneider-electric" for product "Ecostruxure Operator Terminal Expert" | <= 3.0 Search vendor "Schneider-electric" for product "Ecostruxure Operator Terminal Expert" and version " <= 3.0" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Operator Terminal Expert Search vendor "Schneider-electric" for product "Ecostruxure Operator Terminal Expert" | 3.1 Search vendor "Schneider-electric" for product "Ecostruxure Operator Terminal Expert" and version "3.1" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Ecostruxure Operator Terminal Expert Search vendor "Schneider-electric" for product "Ecostruxure Operator Terminal Expert" | 3.1 Search vendor "Schneider-electric" for product "Ecostruxure Operator Terminal Expert" and version "3.1" | sp1 |
Affected
|