A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.
References
Link | Resource |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-343-09/ | Vendor Advisory |
Configurations
History
03 Feb 2022, 16:10
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:schneider-electric:modicon_m258_firmware:*:*:*:*:*:*:*:* |
31 Jan 2022, 19:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:se:modicon_m258:-:*:*:*:*:*:*:* cpe:2.3:a:se:somachine_motion:*:*:*:*:*:*:*:* |
cpe:2.3:a:schneider-electric:somachine:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:modicon_m258:-:*:*:*:*:*:*:* cpe:2.3:a:schneider-electric:somachine_motion:*:*:*:*:*:*:*:* |
26 Aug 2021, 14:43
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:se:modicon_m258:-:*:*:*:*:*:*:* |
23 Aug 2021, 17:30
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:schneider-electric:somachine_motion:*:*:*:*:*:*:*:* |
cpe:2.3:a:se:somachine:*:*:*:*:*:*:*:* cpe:2.3:a:se:somachine_motion:*:*:*:*:*:*:*:* |
19 Aug 2021, 18:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:se:modicon_m258_firmware:*:*:*:*:*:*:*:* |
Information
Published : 2020-12-11 01:15
Updated : 2024-02-04 21:23
NVD link : CVE-2020-28220
Mitre link : CVE-2020-28220
CVE.ORG link : CVE-2020-28220
JSON object : View
Products Affected
schneider-electric
- somachine
- somachine_motion
- modicon_m258
- modicon_m258_firmware
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer