First published: Mon Jan 25 2021(Updated: )
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Operator Terminal Expert | =3.1 | |
Schneider Electric EcoStruxure Operator Terminal Expert | =3.1-sp1a | |
Schneider Electric HMI STO 501 | ||
Schneider Electric HMI Sto 511 | ||
Schneider Electric HMI STO 512 | ||
Schneider Electric HMI STO 531 | ||
Schneider Electric HMI STO 532 | ||
Schneider Electric HMiG3UFC | ||
Schneider Electric HMIG3X | ||
Schneider Electric HMIG5U | ||
Schneider Electric HMIG5U | ||
Schneider-electric Hmist6200 | ||
Schneider Electric HMIST6400 | ||
Schneider Electric HMIST6500 | ||
Schneider Electric HMIST6600 | ||
Schneider Electric Hmist6700 | ||
Schneider-electric Pro-face Blue | =3.1 | |
Schneider-electric Pro-face Blue | =3.1-sp1a | |
Schneider Electric GP-4104G | ||
Schneider Electric GP-4104W | ||
Schneider-electric GP-4105G | ||
Schneider Electric GP-4105W | ||
Schneider-electric Gp-4106g | ||
Schneider-electric GP-4106w | ||
Schneider Electric GP-4107G | ||
Schneider-electric GP-4107W | ||
Schneider-electric Sp-5400wa | ||
Schneider-electric Sp-5500tp | ||
Schneider-electric Sp-5500wa | ||
Schneider Electric SP-5600TA | ||
Schneider-electric Sp-5600tp | ||
Schneider-electric Sp-5600wa | ||
Schneider-electric Sp-5660tp | ||
Schneider-electric Sp-5700tp | ||
Schneider-electric Sp-5700wc | ||
Schneider-electric Sp-5800wc | ||
Schneider-electric Sp-5b00 | ||
Schneider-electric Sp-5b10 | ||
Schneider-electric Sp-5b41 | ||
Schneider-electric St-6200wa | ||
Schneider-electric St-6400wa | ||
Schneider-electric St-6500wa | ||
Schneider-electric St-6600wa | ||
Schneider Electric ST-6700WA |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28221 is a CWE-20: Improper Input Validation vulnerability that exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE.
The severity of CVE-2020-28221 is critical with a severity score of 9.8.
The affected software versions of CVE-2020-28221 are Schneider-electric Ecostruxure Operator Terminal Expert 3.1 and Schneider-electric Pro-face Blue 3.1.
CVE-2020-28221 exploits the vulnerability by causing arbitrary code execution when the Ethernet Download feature is enabled on the HMI.
To fix CVE-2020-28221, it is recommended to follow the guidelines provided by Schneider Electric in their security advisory.