CVE-2020-28212: Critical severity ecostruxure control expert vulnerability
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-28212?
CVE-2020-28212 is a vulnerability that allows unauthorized command execution in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) when a brute force attack is done over Modbus.
What is the severity of CVE-2020-28212?
The severity of CVE-2020-28212 is critical with a CVSS score of 9.8.
How does CVE-2020-28212 affect Schneider-electric Ecostruxure Control Expert?
CVE-2020-28212 affects all versions of Schneider-electric Ecostruxure Control Expert.
How can CVE-2020-28212 be exploited?
CVE-2020-28212 can be exploited through a brute force attack over Modbus.
Is there a fix available for CVE-2020-28212?
Yes, a fix is available for CVE-2020-28212. Please refer to the vendor's website for patch details.