CVE-2020-28221
26.01.2021, 18:15
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | ecostruxure_operator_terminal_expert | 3.1 |
schneider-electric | ecostruxure_operator_terminal_expert | 3.1:sp1a |
schneider-electric | pro-face_blue | 3.1 |
schneider-electric | pro-face_blue | 3.1:sp1a |
𝑥
= Vulnerable software versions
Common Weakness Enumeration