Vulnerabilities (CVE)

Filtered by vendor Schneider-electric Subscribe
Filtered by product Ecostruxure Operator Terminal Expert
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7494 1 Schneider-electric 1 Ecostruxure Operator Terminal Expert 2020-06-19 6.8 MEDIUM 7.8 HIGH
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
CVE-2020-7493 1 Schneider-electric 1 Ecostruxure Operator Terminal Expert 2020-06-17 6.8 MEDIUM 7.8 HIGH
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.