CVE-2020-7559

A CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.

Date published : 2020-11-19

https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1140

https://www.se.com/ww/en/download/document/SEVD-2020-315-07