Security Advisory
CVE-2020-7495
5.5
MEDIUM
Vulnerability Description
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.
Published Date
June 16, 2020
Official Source
NIST NVD Advisory