Description
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Published: 2021-01-25
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-20705 A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
History

No history.

Subscriptions

Schneider-electric Ecostruxure Operator Terminal Expert Gp-4104g Gp-4104w Gp-4105g Gp-4105w Gp-4106g Gp-4106w Gp-4107g Gp-4107w Hmi Sto 501 Hmi Sto 511 Hmi Sto 512 Hmi Sto 531 Hmi Sto 532 Hmig3u Hmig3x Hmig5u Hmig5u2 Hmist6200 Hmist6400 Hmist6500 Hmist6600 Hmist6700 Pro-face Blue Sp-5400wa Sp-5500tp Sp-5500wa Sp-5600ta Sp-5600tp Sp-5600wa Sp-5660tp Sp-5700tp Sp-5700wc Sp-5800wc Sp-5b00 Sp-5b10 Sp-5b41 St-6200wa St-6400wa St-6500wa St-6600wa St-6700wa
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T16:33:58.933Z

Reserved: 2020-11-05T00:00:00.000Z

Link: CVE-2020-28221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-26T18:15:47.600

Modified: 2024-11-21T05:22:30.077

Link: CVE-2020-28221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses