Description
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Published: 2021-01-25
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-20705 A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
History

No history.

Subscriptions

Schneider-electric Ecostruxure Operator Terminal Expert Gp-4104g Gp-4104w Gp-4105g Gp-4105w Gp-4106g Gp-4106w Gp-4107g Gp-4107w Hmi Sto 501 Hmi Sto 511 Hmi Sto 512 Hmi Sto 531 Hmi Sto 532 Hmig3u Hmig3x Hmig5u Hmig5u2 Hmist6200 Hmist6400 Hmist6500 Hmist6600 Hmist6700 Pro-face Blue Sp-5400wa Sp-5500tp Sp-5500wa Sp-5600ta Sp-5600tp Sp-5600wa Sp-5660tp Sp-5700tp Sp-5700wc Sp-5800wc Sp-5b00 Sp-5b10 Sp-5b41 St-6200wa St-6400wa St-6500wa St-6600wa St-6700wa
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-04T16:33:58.933Z

Reserved: 2020-11-05T00:00:00.000Z

Link: CVE-2020-28221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-26T18:15:47.600

Modified: 2024-11-21T05:22:30.077

Link: CVE-2020-28221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses