First published: Mon Jan 25 2021(Updated: )
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Operator Terminal Expert | =3.1 | |
Schneider-electric Ecostruxure Operator Terminal Expert | =3.1-sp1a | |
Schneider-electric Hmi Sto 501 | ||
Schneider-electric Hmi Sto 511 | ||
Schneider-electric Hmi Sto 512 | ||
Schneider-electric Hmi Sto 531 | ||
Schneider-electric Hmi Sto 532 | ||
Schneider-electric Hmig3u | ||
Schneider-electric Hmig3x | ||
Schneider-electric Hmig5u | ||
Schneider-electric Hmig5u2 | ||
Schneider-electric Hmist6200 | ||
Schneider-electric Hmist6400 | ||
Schneider-electric Hmist6500 | ||
Schneider-electric Hmist6600 | ||
Schneider-electric Hmist6700 | ||
Schneider-electric Pro-face Blue | =3.1 | |
Schneider-electric Pro-face Blue | =3.1-sp1a | |
Schneider-electric Gp-4104g | ||
Schneider-electric Gp-4104w | ||
Schneider-electric Gp-4105g | ||
Schneider-electric Gp-4105w | ||
Schneider-electric Gp-4106g | ||
Schneider-electric Gp-4106w | ||
Schneider-electric Gp-4107g | ||
Schneider-electric Gp-4107w | ||
Schneider-electric Sp-5400wa | ||
Schneider-electric Sp-5500tp | ||
Schneider-electric Sp-5500wa | ||
Schneider-electric Sp-5600ta | ||
Schneider-electric Sp-5600tp | ||
Schneider-electric Sp-5600wa | ||
Schneider-electric Sp-5660tp | ||
Schneider-electric Sp-5700tp | ||
Schneider-electric Sp-5700wc | ||
Schneider-electric Sp-5800wc | ||
Schneider-electric Sp-5b00 | ||
Schneider-electric Sp-5b10 | ||
Schneider-electric Sp-5b41 | ||
Schneider-electric St-6200wa | ||
Schneider-electric St-6400wa | ||
Schneider-electric St-6500wa | ||
Schneider-electric St-6600wa | ||
Schneider-electric St-6700wa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28221 is a CWE-20: Improper Input Validation vulnerability that exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE.
The severity of CVE-2020-28221 is critical with a severity score of 9.8.
The affected software versions of CVE-2020-28221 are Schneider-electric Ecostruxure Operator Terminal Expert 3.1 and Schneider-electric Pro-face Blue 3.1.
CVE-2020-28221 exploits the vulnerability by causing arbitrary code execution when the Ethernet Download feature is enabled on the HMI.
To fix CVE-2020-28221, it is recommended to follow the guidelines provided by Schneider Electric in their security advisory.