CVE-2020-7520
published 2020-07-23CVE-2020-7520: A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could…
PriorityP421medium4.7CVSS 3.1
AVNACHPRNUIRSCCLILAN
EPSS
0.93%
56.5th percentile
A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering workstation to modify a Windows registry key which would divert all traffic updates to go through a server in the attacker's possession. A man-in-the-middle attack is then used to complete the exploit.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | software_update_utility | <= 2.4.0 | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Geutebruck Remote Command Execution
suricata·2018-07-02
CVE-2018-7520 ET EXPLOIT Geutebruck Remote Command Execution
ET EXPLOIT Geutebruck Remote Command Execution
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Geutebruck Remote Command Execution"; flow:established,to_server; http.uri; content:"/uapi-cgi/viewer/simple_loglistjs.cgi?"; fast_pattern; content:"/bin/sh"; reference:url,exploit-db.com/exploits/44957/; reference:cve,2018-7520; classtype:attempted-user; sid:2025769; rev:2; metadata:attack_target IoT, created_at 2018_07_02, cve CVE_2018_7520, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2020_08_25;)
No public exploits indexed.
No writeups or analysis indexed.
2020-07-23
Published