A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Ecostruxure Operator Terminal Expert
Subscribe
Gp-4104g
Subscribe
Gp-4104w
Subscribe
Gp-4105g
Subscribe
Gp-4105w
Subscribe
Gp-4106g
Subscribe
Gp-4106w
Subscribe
Gp-4107g
Subscribe
Gp-4107w
Subscribe
Hmi Sto 501
Subscribe
Hmi Sto 511
Subscribe
Hmi Sto 512
Subscribe
Hmi Sto 531
Subscribe
Hmi Sto 532
Subscribe
Hmig3u
Subscribe
Hmig3x
Subscribe
Hmig5u
Subscribe
Hmig5u2
Subscribe
Hmist6200
Subscribe
Hmist6400
Subscribe
Hmist6500
Subscribe
Hmist6600
Subscribe
Hmist6700
Subscribe
Pro-face Blue
Subscribe
Sp-5400wa
Subscribe
Sp-5500tp
Subscribe
Sp-5500wa
Subscribe
Sp-5600ta
Subscribe
Sp-5600tp
Subscribe
Sp-5600wa
Subscribe
Sp-5660tp
Subscribe
Sp-5700tp
Subscribe
Sp-5700wc
Subscribe
Sp-5800wc
Subscribe
Sp-5b00
Subscribe
Sp-5b10
Subscribe
Sp-5b41
Subscribe
St-6200wa
Subscribe
St-6400wa
Subscribe
St-6500wa
Subscribe
St-6600wa
Subscribe
St-6700wa
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-20705 | A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.se.com/ww/en/download/document/SEVD-2021-012-01/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-04T16:33:58.933Z
Reserved: 2020-11-05T00:00:00
Link: CVE-2020-28221
No data.
Status : Modified
Published: 2021-01-26T18:15:47.600
Modified: 2024-11-21T05:22:30.077
Link: CVE-2020-28221
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD