CVE-2020-7490
Published Apr 22, 2020
Last updated 3 years ago
Overview
- Description
- A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product.
- Source
- cybersecurity@se.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:basic:*:*:*", "vulnerable": true, "matchCriteriaId": "74EEFAF2-57EB-4DA0-9917-AD45CFF223F7", "versionEndIncluding": "1.0" }, { "criteria": "cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "BD560E4B-DE63-4DA4-8E1D-5E261269410A", "versionEndIncluding": "6.2" }, { "criteria": "cpe:2.3:a:schneider-electric:vijeo_designer:1.1:-:*:*:basic:*:*:*", "vulnerable": true, "matchCriteriaId": "165A74FC-8710-4C1A-9961-E1064D7465D1" }, { "criteria": "cpe:2.3:a:schneider-electric:vijeo_designer:1.1:hotfix_15:*:*:basic:*:*:*", "vulnerable": true, "matchCriteriaId": "7C091A26-D571-4E24-A4E8-E7EBEAA9899E" }, { "criteria": "cpe:2.3:a:schneider-electric:vijeo_designer:6.9:-:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "A688681A-6CC3-4B9B-8808-DC983D7F44F4" }, { "criteria": "cpe:2.3:a:schneider-electric:vijeo_designer:6.9:sp9:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "2D00383B-4424-46DB-AC35-6093F489D678" } ], "operator": "OR" } ] } ]