PT-2019-6004 · Schneider Electric · Ecostruxure Building Operation Webstation

CVE-2020-28210

·

Published

2019-11-19

·

Updated

2026-05-28

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EcoStruxure Building Operation WebStation versions 2.0 through 3.1
Description A Cross-site Scripting issue exists due to improper neutralization of input during web page generation, allowing an attacker to inject HTML and JavaScript code into a user's browser. This could be exploited by a remote attacker to execute arbitrary code.
Recommendations For versions 2.0 through 3.1, update to a version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the WebStation interface to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04280
CVE-2020-28210

Affected Products

Ecostruxure Building Operation Webstation