8.8

CVE-2020-7501

A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.

Data is provided by the National Vulnerability Database (NVD)
Schneider-electricVijeo Designer SwEditionbasic Version <= 1.0
Schneider-electricVijeo Designer SwEdition- Version <= 6.2
Schneider-electricVijeo Designer Version1.1 Update- SwEditionbasic
Schneider-electricVijeo Designer Version1.1 Updatehotfix_15 SwEditionbasic
Schneider-electricVijeo Designer Version6.9 Update- SwEdition-
Schneider-electricVijeo Designer Version6.9 Updatesp9 SwEdition-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.534
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.