{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-28T14:26:57.229","vulnerabilities":[{"cve":{"id":"CVE-2020-7474","sourceIdentifier":"cybersecurity@se.com","published":"2020-03-23T19:15:12.337","lastModified":"2026-06-17T03:24:51.160","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL."},{"lang":"es","value":"Una CWE-427: Se presenta una vulnerabilidad  de Elemento de Ruta de Búsqueda No Controlada en ProSoft Configurator (versiones v1.002 y anteriores), para el módulo PMEPXM0100 (H), que podría causar la ejecución de código no confiable cuando se usa un doble clic para abrir un archivo de proyecto que puede desencadenar en una ejecución de una DLL maliciosa."}],"affected":[{"source":"cybersecurity@se.com","affectedData":[{"vendor":"n/a","product":"ProSoft Configurator v1.002 and prior, for the PMEPXM0100 (H) module","versions":[{"version":"ProSoft Configurator v1.002 and prior, for the PMEPXM0100 (H) module","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","baseScore":4.4,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"cybersecurity@se.com","type":"Secondary","description":[{"lang":"en","value":"CWE-427"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-427"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:schneider-electric:pmepxm0100_prosoft_configurator:*:*:*:*:*:*:*:*","versionEndIncluding":"1.002","matchCriteriaId":"9B290E74-3A34-4AA1-B4F4-8C0233C25F46"}]}]}],"references":[{"url":"https://www.se.com/ww/en/download/document/SEVD-2020-042-01/","source":"cybersecurity@se.com","tags":["Vendor Advisory"]},{"url":"https://www.se.com/ww/en/download/document/SEVD-2020-042-01/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}