The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric PLC Simulator for EcoStruxure™ Control Expert prior to v15.0 SP1
- Schneider Electric PLC Simulator for Unity Pro (former name of EcoStruxure™ Control Expert) all versions
- Schneider Electric PLC Simulator for EcoStruxure™ Process Expert all versions
- Summary
- A CWE-863: Incorrect Authorization vulnerability exists that could cause bypass of authentication when overwriting memory using a debugger.
- Remediation
- EcoStruxure™ Control Expert Version 15.0 SP1 product includes a fix for the vulnerability CVE-2020-7559 and is available for download here: https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_15SP1 Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center if you need assistance removing a patch. If customers choose not to apply the remediation provided above, they should immediately follow the recommendations in the Mitigation section below to reduce the risk of exploit.
