PT-2020-5820 · Schneider Electric · Ecostruxure Building Operation Webreports
Published
2020-11-10
·
Updated
2022-01-31
·
CVE-2020-7569
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
EcoStruxure Building Operation WebReports versions V1.9 through V3.1
Description:
A vulnerability exists due to the incorrect verification of user-supplied files, allowing an authenticated remote user to upload arbitrary files and achieve remote code execution. This issue is related to the unrestricted upload of files with dangerous types.
Recommendations:
For versions V1.9 through V3.1, update to a version that includes the fix for this issue to prevent remote code execution.
As a temporary workaround, consider restricting access to file upload functionality until a patch is available.
Avoid using the file upload feature in the affected WebReports versions until the issue is resolved.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Building Operation Webreports