CVE-2020-7500
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Mtn6501 0001 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Mtn6501 0002 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Mtn6260 0410 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Mtn6260 0415 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Mtn6260 0310 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.2 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Mtn6260 0315 | All versions |
References (2)
Source: cybersecurity@se.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.