CVE detail
CVE-2020-7480 — CVE-2020-7480
Published 2020-03-23 · Modified 2026-06-17 · Vendor schneider-electric · Product andover_continuum_9680_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0154
EPSS probability
exploitation probability, 30d
72.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an application's processing of XML data.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References