Publisher not identified
EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10)
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2020-7475 | 23 Mar 2020 | EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10) | After downloading the new version, found in the Download Links section below, all of the following steps are required to remediate the vulnerability: STEP 1: Update software and firmware: • On the engineering workstation: o Recommended remediation: update to EcoStruxure Control Expert V15.0 (Available in the Download Links section) • On the Modicon M340 controller: update to firmware V3.20 or above (Available in the Download Links section) • On the Modicon M580 controller: update to firmware V3.10 or above (Available in the Download Links section) STEP 2: Update projects in Ecostruxure Control Expert by: • Setting up an application password in the project properties • Changing the version of the controller firmware to match the new firmware version of the target controller STEP 3: Rebuild and transfer projects in EcoStruxure Control Expert: • Rebuild all current projects • Transfer them to Modicon controllers STEP 4: Configure the Access Controls on Modicon controllers: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.