A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
Ecostruxure Operator Terminal Expert Subscribe
Gp-4104g Subscribe
Gp-4104w Subscribe
Gp-4105g Subscribe
Gp-4105w Subscribe
Gp-4106g Subscribe
Gp-4106w Subscribe
Gp-4107g Subscribe
Gp-4107w Subscribe
Hmi Sto 501 Subscribe
Hmi Sto 511 Subscribe
Hmi Sto 512 Subscribe
Hmi Sto 531 Subscribe
Hmi Sto 532 Subscribe
Hmig5u2 Subscribe
Hmist6200 Subscribe
Hmist6400 Subscribe
Hmist6500 Subscribe
Hmist6600 Subscribe
Hmist6700 Subscribe
Pro-face Blue Subscribe
Sp-5400wa Subscribe
Sp-5500tp Subscribe
Sp-5500wa Subscribe
Sp-5600ta Subscribe
Sp-5600tp Subscribe
Sp-5600wa Subscribe
Sp-5660tp Subscribe
Sp-5700tp Subscribe
Sp-5700wc Subscribe
Sp-5800wc Subscribe
Sp-5b00 Subscribe
Sp-5b10 Subscribe
Sp-5b41 Subscribe
St-6200wa Subscribe
St-6400wa Subscribe
St-6500wa Subscribe
St-6600wa Subscribe
St-6700wa Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-20705 A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T16:33:58.933Z

Reserved: 2020-11-05T00:00:00

Link: CVE-2020-28221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-26T18:15:47.600

Modified: 2024-11-21T05:22:30.077

Link: CVE-2020-28221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses