← Back

CVE-2020-7500

nvd nist
Published: Jun 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.

Affected (6)

Mtn6501 0001 Firmware
Mtn6501 0002 Firmware
Mtn6260 0410 Firmware
Mtn6260 0415 Firmware
Mtn6260 0310 Firmware
Mtn6260 0315 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.2
Running on/withPlatform Versions
Schneider Electric
Mtn6501 0001
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.2
Running on/withPlatform Versions
Schneider Electric
Mtn6501 0002
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.2
Running on/withPlatform Versions
Schneider Electric
Mtn6260 0410
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.2
Running on/withPlatform Versions
Schneider Electric
Mtn6260 0415
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.2
Running on/withPlatform Versions
Schneider Electric
Mtn6260 0310
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.2
Running on/withPlatform Versions
Schneider Electric
Mtn6260 0315
All versions

References (2)

Source: cybersecurity@se.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.