← Vulnerability feed

Vulnerability record · CVE-2020-7501 · published 16 June 2020

CVE-2020-7501: Schneider-electric vijeo designer hard-coded credentials vulnerability

Schneider Electric · Vijeo Designer

A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.

8.8 CVSS 3.1 High EPSS 1.1% · top 35.2% CWE-798 · Hard-coded credentials
8.8CVSS 3.1 base score, v2 6.5
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7501 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-22704Schneider-electric vijeo designer path traversal vulnerabilityA CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all …EPSS 1.3%7.8CVE-2024-8306Schneider-electric vijeo designer improper privilege management vulnerabilityCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability…EPSS 0.21%7.8CVE-2021-22817Schneider-electric hmibmuhi29d2801 firmware incorrect default permissions vulnerabilityA CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to loca…EPSS 0.20%7.8CVE-2021-22705Schneider-electric vijeo designer memory buffer overflow vulnerabilityImproper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized acces…EPSS 0.25%7.8CVE-2020-7490Schneider-electric vijeo designer untrusted search path vulnerabilityA CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), whi…EPSS 0.46%10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed

Source: NIST National Vulnerability Database (record CVE-2020-7501), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.