CVE-2020-28220: Schneider Electric Modicon m258 Firmware
Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.
Affected products
- Schneider Electric Modicon m258 Firmware: before 5.0.4.11 (fixed in 5.0.4.11)
- Schneider Electric Somachine: any version
- Schneider Electric Somachine Motion: any version
Published 2020-12-11. Last modified 2026-06-17.