CVE-2020-7489: Schneider Electric Ecostruxure Machine Expert
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the transference of malicious code to the controller.
Affected products
- Schneider Electric Ecostruxure Machine Expert: any version
- Schneider Electric Modicon m100 Firmware: any version
- Schneider Electric Modicon m200 Firmware: any version
- Schneider Electric Modicon m221 Firmware: any version
- Schneider Electric Somachine Basic: any version
Published 2020-04-22. Last modified 2026-06-17.