← Vulnerability feed

Vulnerability record · CVE-2020-7490 · published 22 April 2020

CVE-2020-7490: Schneider-electric vijeo designer untrusted search path vulnerability

Schneider Electric · Vijeo Designer

A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product.

7.8 CVSS 3.1 High EPSS 0.46% · top 62.9% CWE-426 · Untrusted search path
7.8CVSS 3.1 base score, v2 6.9
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-22704Schneider-electric vijeo designer path traversal vulnerabilityA CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all …EPSS 1.3%8.8CVE-2020-7501Schneider-electric vijeo designer hard-coded credentials vulnerabilityA CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and pri…EPSS 1.1%7.8CVE-2024-8306Schneider-electric vijeo designer improper privilege management vulnerabilityCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability…EPSS 0.21%7.8CVE-2021-22817Schneider-electric hmibmuhi29d2801 firmware incorrect default permissions vulnerabilityA CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to loca…EPSS 0.20%7.8CVE-2021-22705Schneider-electric vijeo designer memory buffer overflow vulnerabilityImproper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized acces…EPSS 0.25%7.8CVE-2012-1854Microsoft Office VBE6.dll Untrusted Search Path Privilege EscalationVBE6.dll in Microsoft Office 2003 SP3, 2007 SP2/SP3, 2010 Gold/SP1, Microsoft VBA, and the Summit Microsoft VBA SDK loads a library from an untrusted…KEVEPSS 21%analysed7.8CVE-2022-23748Audinate Dante mDNSResponder.exe DLL sideloading flawmDNSResponder.exe in Audinate's Dante Application Library improperly specifies how it loads a DLL, including the folder and conditions, allowing a ma…KEVEPSS 9.1%analysed7.8CVE-2022-22047Windows CSRSS elevation of privilege via untrusted search pathCVE-2022-22047 is an elevation of privilege flaw in the Windows Client Server Run-time Subsystem (CSRSS), classified as CWE-426 (untrusted search pat…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2020-7490), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.