CVE-2020-28221

A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
schneiderCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
schneider-electricecostruxure_operator_terminal_expert
3.1
schneider-electricecostruxure_operator_terminal_expert
3.1:sp1a
schneider-electricpro-face_blue
3.1
schneider-electricpro-face_blue
3.1:sp1a
𝑥
= Vulnerable software versions