Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY1 SECURITY RECORD

Publisher not identified

EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions)

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2020-7560 11 Dec 2020 EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions) EcoStruxure Control Expert v15.0 SP1 product includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_15SP1 Contact Schneider Electric’s Customer Care Center if you need assistance removing a patch. If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit. If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Store the project files in a secure storage and restrict the access to only trusted users • When exchanging files over the network, use secure communication protocols • Encrypt project files when stored • Only open project files received from trusted source Important Note: • The fix is provided through the additional feature “file encryption”, for further information on the feature and how to set it up please refers to the chapter “file encryption” of the help file available in the EcoStruxure Control Expert v15.0 SP1. • This feature is proposed by default when creating a new project. • This feature is also available, after selecting “project” in structural view, in the “Edit/ Properties/ Project & Controller Protection” menu. • For new projects: o Customers are recommended to apply this feature to all new projects. • For existing projects: o Customers are recommended to apply this feature to the existing projects coming from trusted source. For .sta project files, as a reminder, project modification can be done in connected mode to prevent desynchronization and keep the controller in RUN state. • It is possible to set a security level specific to the Derived Function Blocks (DFB) in addition to the file encryption feature. Please refer to the chapter "How to protect a DFB type" in the EcoStruxure Control Expert help file for further information. • Customers are recommended to share project files only when configured with the encryption feature described above. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.