CVE-2020-28221: Input Validation
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-28221?
CVE-2020-28221 is a CWE-20: Improper Input Validation vulnerability that exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE.
What is the severity of CVE-2020-28221?
The severity of CVE-2020-28221 is critical with a severity score of 9.8.
Which software versions are affected by CVE-2020-28221?
The affected software versions of CVE-2020-28221 are Schneider-electric Ecostruxure Operator Terminal Expert 3.1 and Schneider-electric Pro-face Blue 3.1.
How does CVE-2020-28221 exploit the vulnerability?
CVE-2020-28221 exploits the vulnerability by causing arbitrary code execution when the Ethernet Download feature is enabled on the HMI.
How can I fix CVE-2020-28221?
To fix CVE-2020-28221, it is recommended to follow the guidelines provided by Schneider Electric in their security advisory.