Vulnerability Details CVE-2020-7500
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-7500
-
cpe:2.3:h:schneider-electric:mtn6260-0310:-
-
cpe:2.3:h:schneider-electric:mtn6260-0315:-
-
cpe:2.3:h:schneider-electric:mtn6260-0410:-
-
cpe:2.3:h:schneider-electric:mtn6260-0415:-
-
cpe:2.3:h:schneider-electric:mtn6501-0001:-
-
cpe:2.3:h:schneider-electric:mtn6501-0002:-
-
cpe:2.3:o:schneider-electric:mtn6260-0310_firmware:*
-
cpe:2.3:o:schneider-electric:mtn6260-0315_firmware:*
-
cpe:2.3:o:schneider-electric:mtn6260-0410_firmware:*
-
cpe:2.3:o:schneider-electric:mtn6260-0415_firmware:*
-
cpe:2.3:o:schneider-electric:mtn6501-0001_firmware:*
-
cpe:2.3:o:schneider-electric:mtn6501-0002_firmware:*