{"api_version":"v1","generated_at":"2026-10-10T09:40:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-publisher-not-identified-ecostruxuretm-control-expert-all-versions-and-unity-pro-former-name-of-ecostruxuretm-12947aca7340","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"EcoStruxure\u2122 Control Expert (all versions) and Unity Pro (former name of EcoStruxure\u2122 Control Expert) (all versions)","next_cursor":null,"observations":[{"affected":"EcoStruxure\u2122 Control Expert (all versions) and Unity Pro (former name of EcoStruxure\u2122 Control Expert) (all versions)","affected_versions_present":true,"cve_id":"CVE-2020-7560","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-7560","fixed":"EcoStruxure Control Expert v15.0 SP1 product includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_15SP1 Contact Schneider Electric\u2019s Customer Care Center if you need assistance removing a patch. If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit. If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: \u2022 Store the project files in a secure storage and restrict the access to only trusted users \u2022 When exchanging files over the network, use secure communication protocols \u2022 Encrypt project files when stored \u2022 Only open project files received from trusted source Important Note: \u2022 The fix is provided through the additional feature \u201cfile encryption\u201d, for further information on the feature and how to set it up please refers to the chapter \u201cfile encryption\u201d of the help file available in the EcoStruxure Control Expert v15.0 SP1. \u2022 This feature is proposed by default when creating a new project. \u2022 This feature is also available, after selecting \u201cproject\u201d in structural view, in the \u201cEdit/ Properties/ Project & Controller Protection\u201d menu. \u2022 For new projects: o Customers are recommended to apply this feature to all new projects. \u2022 For existing projects: o Customers are recommended to apply this feature to the existing projects coming from trusted source. For .sta project files, as a reminder, project modification can be done in connected mode to prevent desynchronization and keep the controller in RUN state. \u2022 It is possible to set a security level specific to the Derived Function Blocks (DFB) in addition to the file encryption feature. Please refer to the chapter \"How to protect a DFB type\" in the EcoStruxure Control Expert help file for further information. \u2022 Customers are recommended to share project files only when configured with the encryption feature described above. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.","last_modified":"2024-08-04T09:33:19.451Z","patch_url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2020-343-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2020-343-01_EcoStruxure_Control_Expert_Process_Expert_RemoteConnect_Security_Notification_V2.0.pdf","primary_source":"","published":"2020-12-11T00:52:30.000Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"Publisher not identified"}}
