Vulnerability Details CVE-2020-7480
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an application's processing of XML data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-7480
-
cpe:2.3:h:schneider-electric:andover_continuum_5720:-
-
cpe:2.3:h:schneider-electric:andover_continuum_5740:-
-
cpe:2.3:h:schneider-electric:andover_continuum_9200:-
-
cpe:2.3:h:schneider-electric:andover_continuum_9680:-
-
cpe:2.3:h:schneider-electric:andover_continuum_9702:-
-
cpe:2.3:h:schneider-electric:andover_continuum_9900:-
-
cpe:2.3:h:schneider-electric:andover_continuum_9924:-
-
cpe:2.3:h:schneider-electric:andover_continuum_9940:-
-
cpe:2.3:h:schneider-electric:andover_continuum_9941:-
-
cpe:2.3:h:schneider-electric:andover_continuum_bcx4040:-
-
cpe:2.3:h:schneider-electric:andover_continuum_bcx9640:-
-
cpe:2.3:o:schneider-electric:andover_continuum_5720_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_5740_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_9200_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_9680_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_9702_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_9900_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_9924_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_9940_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_9941_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_bcx4040_firmware:-
-
cpe:2.3:o:schneider-electric:andover_continuum_bcx9640_firmware:-