CWE
20
Advisory Published
Updated

CVE-2020-28221: Input Validation

First published: Mon Jan 25 2021(Updated: )

A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.

Credit: cybersecurity@se.com

Affected SoftwareAffected VersionHow to fix
Schneider-electric Ecostruxure Operator Terminal Expert=3.1
Schneider-electric Ecostruxure Operator Terminal Expert=3.1-sp1a
Schneider-electric Hmi Sto 501
Schneider-electric Hmi Sto 511
Schneider-electric Hmi Sto 512
Schneider-electric Hmi Sto 531
Schneider-electric Hmi Sto 532
Schneider-electric Hmig3u
Schneider-electric Hmig3x
Schneider-electric Hmig5u
Schneider-electric Hmig5u2
Schneider-electric Hmist6200
Schneider-electric Hmist6400
Schneider-electric Hmist6500
Schneider-electric Hmist6600
Schneider-electric Hmist6700
Schneider-electric Pro-face Blue=3.1
Schneider-electric Pro-face Blue=3.1-sp1a
Schneider-electric Gp-4104g
Schneider-electric Gp-4104w
Schneider-electric Gp-4105g
Schneider-electric Gp-4105w
Schneider-electric Gp-4106g
Schneider-electric Gp-4106w
Schneider-electric Gp-4107g
Schneider-electric Gp-4107w
Schneider-electric Sp-5400wa
Schneider-electric Sp-5500tp
Schneider-electric Sp-5500wa
Schneider-electric Sp-5600ta
Schneider-electric Sp-5600tp
Schneider-electric Sp-5600wa
Schneider-electric Sp-5660tp
Schneider-electric Sp-5700tp
Schneider-electric Sp-5700wc
Schneider-electric Sp-5800wc
Schneider-electric Sp-5b00
Schneider-electric Sp-5b10
Schneider-electric Sp-5b41
Schneider-electric St-6200wa
Schneider-electric St-6400wa
Schneider-electric St-6500wa
Schneider-electric St-6600wa
Schneider-electric St-6700wa

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-28221?

    CVE-2020-28221 is a CWE-20: Improper Input Validation vulnerability that exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE.

  • What is the severity of CVE-2020-28221?

    The severity of CVE-2020-28221 is critical with a severity score of 9.8.

  • Which software versions are affected by CVE-2020-28221?

    The affected software versions of CVE-2020-28221 are Schneider-electric Ecostruxure Operator Terminal Expert 3.1 and Schneider-electric Pro-face Blue 3.1.

  • How does CVE-2020-28221 exploit the vulnerability?

    CVE-2020-28221 exploits the vulnerability by causing arbitrary code execution when the Ethernet Download feature is enabled on the HMI.

  • How can I fix CVE-2020-28221?

    To fix CVE-2020-28221, it is recommended to follow the guidelines provided by Schneider Electric in their security advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203