CVE-2020-7495
published 2020-06-16CVE-2020-7495: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure…
medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_operator_terminal_expert | <= 3.0 | — |
| schneider-electric | ecostruxure_operator_terminal_expert | — | — |