Description
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an application's processing of XML data.
Published: 2020-03-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-28605 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an application's processing of XML data.
History

No history.

Subscriptions

Schneider-electric Andover Continuum 5720 Andover Continuum 5720 Firmware Andover Continuum 5740 Andover Continuum 5740 Firmware Andover Continuum 9200 Andover Continuum 9200 Firmware Andover Continuum 9680 Andover Continuum 9680 Firmware Andover Continuum 9702 Andover Continuum 9702 Firmware Andover Continuum 9900 Andover Continuum 9900 Firmware Andover Continuum 9924 Andover Continuum 9924 Firmware Andover Continuum 9940 Andover Continuum 9940 Firmware Andover Continuum 9941 Andover Continuum 9941 Firmware Andover Continuum Bcx4040 Andover Continuum Bcx4040 Firmware Andover Continuum Bcx9640 Andover Continuum Bcx9640 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T09:33:19.649Z

Reserved: 2020-01-21T00:00:00.000Z

Link: CVE-2020-7480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-23T20:15:12.543

Modified: 2024-11-21T05:37:13.777

Link: CVE-2020-7480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses