{"api_version":"v1","generated_at":"2026-10-08T06:05:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-m-and-m-software-fdtcontainer-component-45fc2677bd8b","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"fdtCONTAINER Component","next_cursor":null,"observations":[{"affected":"unspecified < 3.5; 3.5 < 3.5.20304.x; 3.6 < 3.6.20304.x; unspecified < 4.5; 4.5 < 4.5.20304.x; 4.6 < 4.6.20304.x; 3; unspecified \u2264 5.0.5.31","affected_versions_present":true,"cve_id":"CVE-2020-12525","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-12525","fixed":"EcoStruxure\u2122 Control Expert V15.1, available for download below, includes a fix for CVE-2021-22778, CVE-2021-22780, CVE-2021-22781, CVE-2021-22782, CVE-2020-12525: https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_V15.1/ *Upgrading to EcoStruxure\u2122 Control Expert V15.1 is the first step in a two stepsprocess to fully address CVE-2021-22779. To fully address this issue a firmwarerelease will follow. Important Note: \u2022The fix is provided through the additional feature \u201cfile encryption\u201d, forfurther information on the feature and how to set it up please refers to thechapter \u201cfile encryption\u201d of the help file available in the EcoStruxure\u2122Control Expert v15.0 SP1. \u2022This feature is proposed by default when creating a new project. \u2022This feature is also available, after selecting \u201cproject\u201d in structural view, inthe \u201cEdit/ Properties/ Project & Controller Protection\u201d menu. \u2022For new projects: oCustomers are recommended to apply this feature to all newprojects. \u2022For existing projects: oCustomers are recommended to apply this feature to the existingprojects coming from trusted source. For .sta project files, as areminder, project modification can be done in connected mode toprevent desynchronization and keep the controller in RUN state. \u2022It is possible to set a security level specific to the Derived Function Blocks(DFB) in addition to the file encryption feature. Please refer to the chapter\"How to protect a DFB type\" in the EcoStruxure\u2122 Control Expert help filefor further information. \u2022Customers are recommended to share project files only when configuredwith the encryption feature described above. If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit. These mitigations also reduce the risk of exploit for CVE-2021-22779 on all versions of EcoStruxure\u2122 Control Expert, including V15.1: \u2022Store the project files in a secure storage and restrict the access to onlytrusted users \u2022When exchanging files over the network, use secure communicationprotocols \u2022Encrypt project files when stored \u2022Only open project files received from trusted source \u2022Compute a hash of the project files and regularly check the consistency ofthis hash to verify the integrity before usage. \u2022Harden the workstation running EcoStruxure\u2122 Control Expert or Unity Pro Customers using Unity Pro should strongly consider migrating to EcoStruxure\u2122 Control Expert. Please contact your local Schneider Electric technical support for more information.","last_modified":"2024-09-16T23:11:43.568Z","patch_url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-194-01_EcoStruxure_Control_Expert_Process_Expert_SCADAPack_RemoteConnect_Modicon_M580_M340.pdf","primary_source":"","published":"2021-01-22T19:01:56.886Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"M&M Software"}}
